CVE-2015-1208
published 2018-01-09CVE-2015-1208: Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from…
PriorityP422medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
EPSS
1.49%
71.3th percentile
Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from heap and/or stack memory via a crafted MP4 file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.5.3-1 (bookworm) | ffmpeg 7:2.5.3-1 (bookworm) |
| ffmpeg | ffmpeg | < 2.4.6 | 2.4.6 |
| ffmpeg | ffmpeg | >= 0 < 7:2.5.3-1 | 7:2.5.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.5.3-1 | 7:2.5.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.5.3-1 | 7:2.5.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.5.3-1 | 7:2.5.3-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-1208: ffmpeg - Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpe...
vendor_debian·2015·CVSS 5.5
CVE-2015-1208 [MEDIUM] CVE-2015-1208: ffmpeg - Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpe...
Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from heap and/or stack memory via a crafted MP4 file.
Scope: local
bookworm: resolved (fixed in 7:2.5.3-1)
bullseye: resolved (fixed in 7:2.5.3-1)
forky: resolved (fixed in 7:2.5.3-1)
sid: resolved (fixed in 7:2.5.3-1)
trixie: resolved (fixed in 7:2.5.3-1)
GHSA
GHSA-wwpv-hj37-m43g: Integer underflow in the mov_read_default function in libavformat/mov
ghsa_unreviewed·2022-05-14
CVE-2015-1208 [MEDIUM] CWE-191 GHSA-wwpv-hj37-m43g: Integer underflow in the mov_read_default function in libavformat/mov
Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from heap and/or stack memory via a crafted MP4 file.
OSV
CVE-2015-1208: Integer underflow in the mov_read_default function in libavformat/mov
osv·2018-01-09·CVSS 5.5
CVE-2015-1208 [MEDIUM] CVE-2015-1208: Integer underflow in the mov_read_default function in libavformat/mov
Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from heap and/or stack memory via a crafted MP4 file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=3ebd76a9c57558e284e94da367dd23b435e6a6d0https://bugs.chromium.org/p/chromium/issues/detail?id=444546https://github.com/FFmpeg/FFmpeg/blob/n2.4.6/Changeloghttp://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=3ebd76a9c57558e284e94da367dd23b435e6a6d0https://bugs.chromium.org/p/chromium/issues/detail?id=444546https://github.com/FFmpeg/FFmpeg/blob/n2.4.6/Changelog
2018-01-09
Published