Medium severity6.5NVD Advisory· Published Feb 5, 2018· Updated Jun 17, 2026
CVE-2018-6621
CVE-2018-6621
Description
The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of service (out of array read) via a crafted AVI file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/ffmpeg-4&distro=openSUSE%20Tumbleweedpkg:rpm/suse/ffmpeg&distro=SUSE%20Package%20Hub%2012%20SP2
< 4.4-5.2+ 1 more
- (no CPE)range: < 4.4-5.2
- (no CPE)range: < 3.4.2-14.1
Patches
Vulnerability mechanics
References
5- git.ffmpeg.org/gitweb/ffmpeg.git/commit/118e1b0b3370dd1c0da442901b486689efd1654bnvdPatchThird Party Advisory
- github.com/FFmpeg/FFmpeg/commit/22aa37c0fedf14531783189a197542a055959b6cnvdPatchThird Party Advisory
- www.securityfocus.com/bid/102950nvdThird Party AdvisoryVDB Entry
- lists.debian.org/debian-lts-announce/2019/01/msg00006.htmlnvdMailing ListThird Party Advisory
- www.debian.org/security/2018/dsa-4249nvdThird Party Advisory
News mentions
0No linked articles in our index yet.