The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 does not enforce uniqueness of the IHDR (aka image header) chunk in a PNG image, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted image with two or more of these chunks.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ffmpeg | Feb 20, 2019 | Sep 5, 2015 |
| Ffmpeg | — | Upgrade to FFmpeg version 2.8Upgrade to FFmpeg version 2.6.4Upgrade to FFmpeg version 2.5.8Upgrade to FFmpeg version 2.7.2Upgrade to FFmpeg version 2.4.11 | Sep 29, 2017 | Sep 6, 2015 |
| Freebsd | — | Upgrade libavUpgrade mencoderUpgrade ffmpeg2Upgrade gstreamer1-libavUpgrade ffmpegUpgrade mythtvUpgrade mythtv-frontendUpgrade kodiUpgrade handbrakeUpgrade ffmpeg1Upgrade avidemuxUpgrade ffmpeg0Upgrade gstreamer-ffmpegUpgrade ffmpeg-develUpgrade ffmpeg26Upgrade avidemux2Upgrade ffmpeg24Upgrade ffmpeg25Upgrade ffmpeg-011Upgrade ffmpeg23Upgrade avidemux26Upgrade plexhometheaterUpgrade mplayer | Dec 10, 2025 | Sep 20, 2015 |
| Ubuntu | — | Upgrade libavcodec53Upgrade libavformat53 | Apr 4, 2016 | Sep 5, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub