In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted MXF file, which claims a large "nb_index_entries" field in the header but does not contain sufficient backing data, is provided, the loop would consume huge CPU resources, since there is no EOF check inside the loop. Moreover, this big loop can be invoked multiple times if there is more than one applicable data segment in the crafted MXF file.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ffmpegUpgrade ffmpeg4 | Aug 22, 2024 | Sep 7, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Sep 7, 2017 |
| Debian | — | Upgrade ffmpeg | Dec 5, 2017 | Sep 7, 2017 |
| Ffmpeg | — | Upgrade to FFmpeg version 3.0.10Upgrade to FFmpeg version 3.1.11Upgrade to FFmpeg version 2.4.14Upgrade to FFmpeg version 3.3.4Upgrade to FFmpeg version 2.8.13Upgrade to FFmpeg version 3.2.8 | Sep 29, 2017 | Sep 7, 2017 |
| Freebsd | — | Upgrade ffmpegUpgrade mythtv-frontendUpgrade mythtv | Oct 13, 2017 | Oct 12, 2017 |
| Suse | — | Upgrade libswresample-develUpgrade libswresample2Upgrade libpostproc54Upgrade libpostproc-develUpgrade libavresample-develUpgrade libavcodec57Upgrade libswscale4Upgrade libavutil55Upgrade libavfilter6Upgrade libswscale-develUpgrade libavutil-develUpgrade libavformat-develUpgrade libavresample3Upgrade libavdevice57Upgrade ffmpegUpgrade libavformat57Upgrade libavcodec-devel | Sep 16, 2017 | Sep 7, 2017 |
| Ubuntu | — | Upgrade ffmpeg | Nov 19, 2024 | Sep 7, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub