Описание
FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_input_format3 in libavformat/format.c.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 7:3.4.8-0ubuntu0.2 |
| devel | not-affected | 7:4.3.1-1ubuntu1 |
| eoan | ignored | end of life |
| esm-apps/bionic | released | 7:3.4.8-0ubuntu0.2 |
| esm-apps/focal | released | 7:4.2.4-1ubuntu0.1 |
| esm-apps/xenial | released | 7:2.8.17-0ubuntu0.1 |
| esm-infra-legacy/trusty | DNE | |
| focal | released | 7:4.2.4-1ubuntu0.1 |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
Показывать по
EPSS
4.3 Medium
CVSS2
5.5 Medium
CVSS3
Связанные уязвимости
FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_input_format3 in libavformat/format.c.
FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duratio ...
FFmpeg 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_input_format3 in libavformat/format.c.
Уязвимость функции parse_playlist библиотеки libavformat мультимедийной среды Ffmpeg, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
4.3 Medium
CVSS2
5.5 Medium
CVSS3