The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not check for a matching AAC frame syntax element before proceeding with Spectral Band Replication calculations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted AAC data.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ffmpeg | Feb 20, 2019 | Sep 5, 2015 |
| Ffmpeg | — | Upgrade to FFmpeg version 2.8Upgrade to FFmpeg version 2.6.4Upgrade to FFmpeg version 2.5.8Upgrade to FFmpeg version 2.4.11Upgrade to FFmpeg version 2.7.2 | Sep 29, 2017 | Sep 6, 2015 |
| Freebsd | — | Upgrade mplayerUpgrade handbrakeUpgrade ffmpeg-011Upgrade ffmpeg25Upgrade gstreamer-ffmpegUpgrade avidemux2Upgrade avidemux26Upgrade ffmpeg-develUpgrade libavUpgrade ffmpeg0Upgrade ffmpeg24Upgrade ffmpeg26Upgrade kodiUpgrade avidemuxUpgrade mencoderUpgrade mythtv-frontendUpgrade gstreamer1-libavUpgrade ffmpeg1Upgrade ffmpegUpgrade ffmpeg2Upgrade ffmpeg23Upgrade plexhometheaterUpgrade mythtv | Dec 10, 2025 | Sep 20, 2015 |
| Ubuntu | — | Upgrade libavformat53Upgrade libavcodec53 | Apr 4, 2016 | Sep 5, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub