VYPR

rpm package

opensuse/ffmpeg-4&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/ffmpeg-4&distro=openSUSE%20Tumbleweed

Vulnerabilities (92)

  • CVE-2017-17081MedNov 30, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    The gmc_mmx function in libavcodec/x86/mpegvideodsp.c in FFmpeg 2.3 and 3.4 does not properly validate widths and heights, which allows remote attackers to cause a denial of service (integer signedness error and out-of-array read) via a crafted MPEG file.

  • CVE-2017-16840CriNov 21, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar wavelets, related to libavcodec/vc2enc.c and libavcodec/vc2enc_dwt.c.

  • CVE-2017-15672HigNov 6, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to have unspecified impact via a crafted MP4 file, which triggers an out-of-bounds read.

  • CVE-2017-15186MedOct 24, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.

  • CVE-2017-14225HigSep 9, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, leading to a NULL pointer dere

  • CVE-2017-14223MedSep 9, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted ASF file, which claims a large "ict" field in the header but does not contain sufficient backing data, is provid

  • CVE-2017-14222MedSep 9, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MOV file, which claims a large "item_count" field in the header but does not contain sufficient backing data, is provid

  • CVE-2017-14171MedSep 7, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    In libavformat/nsvdec.c in FFmpeg 2.4 and 3.3.3, a DoS in nsv_parse_NSVf_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted NSV file, which claims a large "table_entries_used" field in the header but does not contain sufficient bac

  • CVE-2017-14170MedSep 7, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted MXF file, which claims a large "nb_index_entries" field in the header but does not contain sufficient b

  • CVE-2017-14169HigSep 7, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, which claims a large "item_num" field such as 0xffffffff, is provided. As a result, the variable "item_num" turns negative, bypassing

  • CVE-2017-14059MedAug 31, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    In FFmpeg 3.3.3, a DoS in cine_read_header() due to lack of an EOF check might cause huge CPU and memory consumption. When a crafted CINE file, which claims a large "duration" field in the header but does not contain sufficient backing data, is provided, the image-offset parsing

  • CVE-2017-14058MedAug 31, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    In FFmpeg 2.4 and 3.3.3, the read_data function in libavformat/hls.c does not restrict reload attempts for an insufficient list, which allows remote attackers to cause a denial of service (infinite loop).

  • CVE-2017-14057MedAug 31, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file, which claims a large "name_len" or "count" field in the header but does not contain sufficient backing data, is provided, th

  • CVE-2017-14056MedAug 31, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted RL2 file, which claims a large "frame_count" field in the header but does not contain sufficient backing data, is

  • CVE-2017-14055MedAug 31, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MV file, which claims a large "nb_frames" field in the header but does not contain sufficient backing data, is p

  • CVE-2017-14054MedAug 31, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    In libavformat/rmdec.c in FFmpeg 3.3.3, a DoS in ivr_read_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted IVR file, which claims a large "len" field in the header but does not contain sufficient backing data, is provided, the fi

  • CVE-2017-11665HigJul 27, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    The ff_amf_get_field_value function in libavformat/rtmppkt.c in FFmpeg 3.3.2 allows remote RTMP servers to cause a denial of service (Segmentation Violation and application crash) via a crafted stream.

  • CVE-2017-11399HigJul 17, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    Integer overflow in the ape_decode_frame function in libavcodec/apedec.c in FFmpeg 2.4 through 3.3.2 allows remote attackers to cause a denial of service (out-of-array access and application crash) or possibly have unspecified other impact via a crafted APE file.

  • CVE-2017-7866CriApr 14, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    FFmpeg before 2017-01-23 has an out-of-bounds write caused by a stack-based buffer overflow related to the decode_zbuf function in libavcodec/pngdec.c.

  • CVE-2017-7863CriApr 14, 2017
    affected < 4.4-5.2fixed 4.4-5.2

    FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c.

Page 4 of 5