The h264_slice_header_init function in libavcodec/h264_slice.c in FFmpeg before 2.8.3 does not validate the relationship between the number of threads and the number of slices, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted H.264 data.
CVSS Details
- CVSS 3.1 Base Score: 8.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ffmpeg | Feb 20, 2019 | Dec 23, 2015 |
| Ffmpeg | — | Upgrade to FFmpeg version 2.7.4Upgrade to FFmpeg version 2.4.12Upgrade to FFmpeg version 2.8.3Upgrade to FFmpeg version 2.6.6Upgrade to FFmpeg version 2.5.9 | Sep 29, 2017 | Dec 24, 2015 |
| Suse | — | Upgrade libavformat-develUpgrade libswresample-develUpgrade ffmpegUpgrade libavdevice57Upgrade libavutil55Upgrade libswscale4Upgrade libpostproc54Upgrade libavcodec57Upgrade libavcodec-develUpgrade libavfilter6Upgrade libswscale-develUpgrade libavutil-develUpgrade libavformat57Upgrade libswresample2Upgrade libavresample3Upgrade libavresample-develUpgrade libpostproc-devel | Feb 2, 2016 | Dec 23, 2015 |
| Ubuntu | — | Upgrade ffmpeg | Nov 19, 2024 | Dec 24, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub