The msrle_decode_8_16_24_32 function in msrledec.c in libavcodec in FFmpeg through 1.1.3 does not properly determine certain end pointers, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted Microsoft RLE data.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ffmpeg | Jul 30, 2024 | Mar 9, 2013 |
| Ffmpeg | — | Upgrade to FFmpeg version 1.1.4Upgrade to FFmpeg version 1.0.6Upgrade to FFmpeg version 1.2 | Sep 29, 2017 | Mar 9, 2013 |
| Ubuntu | — | Upgrade libavcodec53Upgrade libavformat53 | Nov 8, 2024 | Mar 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub