CVE-2015-5479
published 2016-04-19CVE-2015-5479: The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero error and…
PriorityP423medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
1.98%
78.5th percentile
The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a file with crafted dimensions.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | — | — |
| libav | libav | <= 11.4 | — |
| libav | libav | >= 0 < 6:9.20-0ubuntu0.14.04.1+esm1 | 6:9.20-0ubuntu0.14.04.1+esm1 |
| opensuse | leap | — | — |
| ubuntu | ubuntu | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libav vulnerabilities
vendor_ubuntu·2016-04-04
CVE-2014-8541 Libav vulnerabilities
Title: Libav vulnerabilities
Summary: Libav could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that Libav incorrectly handled certain malformed media
files. If a user were tricked into opening a crafted media file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2015-5479: ffmpeg - The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 ...
vendor_debian·2015·CVSS 6.5
CVE-2015-5479 [MEDIUM] CVE-2015-5479: ffmpeg - The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 ...
The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a file with crafted dimensions.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-73wj-87qj-vf4x: The ff_h263_decode_mba function in libavcodec/ituh263dec
ghsa_unreviewed·2022-05-14
CVE-2015-5479 [MEDIUM] GHSA-73wj-87qj-vf4x: The ff_h263_decode_mba function in libavcodec/ituh263dec
The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a file with crafted dimensions.
OSV
CVE-2015-5479: The ff_h263_decode_mba function in libavcodec/ituh263dec
osv·2015-10-09·CVSS 6.5
CVE-2015-5479 [MEDIUM] CVE-2015-5479: The ff_h263_decode_mba function in libavcodec/ituh263dec
The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a file with crafted dimensions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-updates/2016-06/msg00105.htmlhttp://www.securityfocus.com/bid/75932http://www.ubuntu.com/usn/USN-2944-1https://blogs.gentoo.org/ago/2015/07/16/libav-divide-by-zero-in-ff_h263_decode_mba/https://git.libav.org/?p=libav.git%3Ba=commitdiff%3Bh=0a49a62f998747cfa564d98d36a459fe70d3299bhttps://libav.org/releases/libav-11.5.changeloghttp://lists.opensuse.org/opensuse-updates/2016-06/msg00105.htmlhttp://www.securityfocus.com/bid/75932http://www.ubuntu.com/usn/USN-2944-1https://blogs.gentoo.org/ago/2015/07/16/libav-divide-by-zero-in-ff_h263_decode_mba/https://git.libav.org/?p=libav.git%3Ba=commitdiff%3Bh=0a49a62f998747cfa564d98d36a459fe70d3299bhttps://libav.org/releases/libav-11.5.changelog
2016-04-19
Published