In Libav through 11.11 and 12.x through 12.1, the smacker_decode_tree function in libavcodec/smacker.c does not properly restrict tree recursion, which allows remote attackers to cause a denial of service (bitstream.c:build_table() out-of-bounds read and application crash) via a crafted Smacker stream.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ffmpeg | Feb 21, 2018 | Nov 13, 2017 |
| Ffmpeg | — | Upgrade to FFmpeg version 1.0 | Jul 20, 2026 | Nov 13, 2017 |
| Gentoo Linux | — | Upgrade media-video/libav. | Nov 27, 2018 | Nov 13, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Nov 13, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub