CVE-2015-3417
published 2015-04-24CVE-2015-3417: Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of…
PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.57%
83.5th percentile
Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | ffmpeg | < ffmpeg 7:2.6.1-1 (bookworm) | ffmpeg 7:2.6.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 2.3.5 | — |
| ffmpeg | ffmpeg | >= 0 < 7:2.6.1-1 | 7:2.6.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.6.1-1 | 7:2.6.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.6.1-1 | 7:2.6.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.6.1-1 | 7:2.6.1-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-3417: ffmpeg - Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h...
vendor_debian·2015·CVSS 6.8
CVE-2015-3417 [MEDIUM] CVE-2015-3417: ffmpeg - Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h...
Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.
Scope: local
bookworm: resolved (fixed in 7:2.6.1-1)
bullseye: resolved (fixed in 7:2.6.1-1)
forky: resolved (fixed in 7:2.6.1-1)
sid: resolved (fixed in 7:2.6.1-1)
trixie: resolved (fixed in 7:2.6.1-1)
GHSA
GHSA-9323-4x78-29mv: Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264
ghsa_unreviewed·2022-05-17
CVE-2015-3417 [MEDIUM] GHSA-9323-4x78-29mv: Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264
Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.
OSV
CVE-2015-3417: Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264
osv·2015-04-24·CVSS 6.8
CVE-2015-3417 [MEDIUM] CVE-2015-3417: Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264
Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2015/Apr/31http://www.debian.org/security/2015/dsa-3288http://www.securityfocus.com/bid/74385http://www.securitytracker.com/id/1032198https://git.libav.org/?p=libav.git%3Ba=blob%3Bf=Changelog%3Bhb=refs/tags/v11.4https://github.com/FFmpeg/FFmpeg/commit/e8714f6f93d1a32f4e4655209960afcf4c185214https://security.gentoo.org/glsa/201705-08http://seclists.org/fulldisclosure/2015/Apr/31http://www.debian.org/security/2015/dsa-3288http://www.securityfocus.com/bid/74385http://www.securitytracker.com/id/1032198https://git.libav.org/?p=libav.git%3Ba=blob%3Bf=Changelog%3Bhb=refs/tags/v11.4https://github.com/FFmpeg/FFmpeg/commit/e8714f6f93d1a32f4e4655209960afcf4c185214https://security.gentoo.org/glsa/201705-08
2015-04-24
Published