Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-8365

Опубликовано: 26 нояб. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8

Описание

The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the data size is consistent with the number of channels, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Smacker data.

РелизСтатусПримечание
artful

not-affected

7:2.8.3-1
bionic

not-affected

7:2.8.3-1
devel

not-affected

7:2.8.3-1
esm-apps/bionic

not-affected

7:2.8.3-1
esm-apps/xenial

not-affected

7:2.8.3-1
esm-infra-legacy/trusty

DNE

precise

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

Показывать по

РелизСтатусПримечание
artful

DNE

bionic

DNE

devel

DNE

esm-infra-legacy/trusty

ignored

precise

released

4:0.8.17-0ubuntu0.12.04.2
precise/esm

DNE

precise was released [4:0.8.17-0ubuntu0.12.04.2]
trusty

ignored

trusty/esm

ignored

upstream

needs-triage

vivid

ignored

end of life

Показывать по

EPSS

Процентиль: 67%
0.00536
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

nvd
около 10 лет назад

The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the data size is consistent with the number of channels, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Smacker data.

debian
около 10 лет назад

The smka_decode_frame function in libavcodec/smacker.c in FFmpeg befor ...

github
больше 3 лет назад

The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the data size is consistent with the number of channels, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Smacker data.

suse-cvrf
около 10 лет назад

Security update for ffmpeg

EPSS

Процентиль: 67%
0.00536
Низкий

6.8 Medium

CVSS2