The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2, when running with certain -probesize values, allows remote attackers to cause a denial of service (crash) via a crafted MP3 file, possibly related to frame size or lack of sufficient "frames to estimate rate."
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ffmpeg | Sep 20, 2017 | Dec 24, 2013 |
| Debian | — | Upgrade libavUpgrade ffmpeg | Jul 30, 2024 | Dec 24, 2013 |
| Ffmpeg | — | Upgrade to FFmpeg version 1.1Upgrade to FFmpeg version 1.0.2Upgrade to FFmpeg version 0.11.3 | Sep 29, 2017 | Dec 24, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub