VYPR
Critical severity9.8NVD Advisory· Published Feb 9, 2017· Updated May 13, 2026

CVE-2016-10191

CVE-2016-10191

Description

Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches.

Affected products

14
  • FFmpeg/Ffmpeg14 versions
    cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*+ 13 more
    • cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*range: <=2.8.9
    • cpe:2.3:a:ffmpeg:ffmpeg:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.2.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.