CVE-2015-1207Double Free in Ffmpeg

CWE-415Double Free6 documents5 sources
Severity
6.5MEDIUMNVD
EPSS
0.5%
top 35.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 6
Latest updateMay 14

Description

Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDgoogle/chrome41.0.2251.0
debiandebian/ffmpeg< ffmpeg 7:2.6.1-1 (bookworm)
Debianffmpeg/ffmpeg< 7:2.6.1-1+3

Also affects: Debian Linux 8.0

🔴Vulnerability Details

2
GHSA
GHSA-xhm7-3cgh-g3g7: Double-free vulnerability in libavformat/mov2022-05-14
OSV
CVE-2015-1207: Double-free vulnerability in libavformat/mov2017-06-06

📋Vendor Advisories

1
Debian
CVE-2015-1207: ffmpeg - Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2...2015

💬Community

2
Bugzilla
CVE-2015-2728 Mozilla: Type confusion in Indexed Database Manager (MFSA 2015-61)2015-06-30
Bugzilla
CVE-2015-2729 Mozilla: Out-of-bound read while computing an oscillator rendering range in Web Audio (MFSA 2015-62)2015-06-30