VYPR
Medium severity6.5OSV Advisory· Published Jan 3, 2018· Updated Jun 17, 2026

CVE-2017-1000460

CVE-2017-1000460

Description

In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • FFmpeg/FfmpegOSV3 versions
    N, dev14.2, n0.11-dev, …+ 2 more
    • (no CPE)range: N, dev14.2, n0.11-dev, …
    • cpe:2.3:a:ffmpeg:ffmpeg:3.4:*:*:*:*:*:*:*
    • (no CPE)range: <n3.4
  • cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
    Range: <=56.0.2924
  • cpe:2.3:a:libav:libav:13_dev0:*:*:*:*:*:*:*
  • Libav/libavcodecllm-fuzzy
  • Range: <56

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.