CVE-2015-6823
published 2015-09-06CVE-2015-6823: The allocate_buffers function in libavcodec/alac.c in FFmpeg before 2.7.2 does not initialize certain context data, which allows remote attackers to cause a…
PriorityP434high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.41%
82.4th percentile
The allocate_buffers function in libavcodec/alac.c in FFmpeg before 2.7.2 does not initialize certain context data, which allows remote attackers to cause a denial of service (segmentation violation) or possibly have unspecified other impact via crafted Apple Lossless Audio Codec (ALAC) data.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.7.2-1 (bookworm) | ffmpeg 7:2.7.2-1 (bookworm) |
| ffmpeg | ffmpeg | <= 2.7.1 | — |
| ffmpeg | ffmpeg | >= 0 < 7:2.7.2-1 | 7:2.7.2-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.7.2-1 | 7:2.7.2-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.7.2-1 | 7:2.7.2-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.7.2-1 | 7:2.7.2-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-6823: ffmpeg - The allocate_buffers function in libavcodec/alac.c in FFmpeg before 2.7.2 does n...
vendor_debian·2015·CVSS 7.5
CVE-2015-6823 [HIGH] CVE-2015-6823: ffmpeg - The allocate_buffers function in libavcodec/alac.c in FFmpeg before 2.7.2 does n...
The allocate_buffers function in libavcodec/alac.c in FFmpeg before 2.7.2 does not initialize certain context data, which allows remote attackers to cause a denial of service (segmentation violation) or possibly have unspecified other impact via crafted Apple Lossless Audio Codec (ALAC) data.
Scope: local
bookworm: resolved (fixed in 7:2.7.2-1)
bullseye: resolved (fixed in 7:2.7.2-1)
forky: resolved (fixed in 7:2.7.2-1)
sid: resolved (fixed in 7:2.7.2-1)
trixie: resolved (fixed in 7:2.7.2-1)
GHSA
GHSA-ppw2-32fh-5wfq: The allocate_buffers function in libavcodec/alac
ghsa_unreviewed·2022-05-14
CVE-2015-6823 [HIGH] GHSA-ppw2-32fh-5wfq: The allocate_buffers function in libavcodec/alac
The allocate_buffers function in libavcodec/alac.c in FFmpeg before 2.7.2 does not initialize certain context data, which allows remote attackers to cause a denial of service (segmentation violation) or possibly have unspecified other impact via crafted Apple Lossless Audio Codec (ALAC) data.
OSV
CVE-2015-6823: The allocate_buffers function in libavcodec/alac
osv·2015-09-06·CVSS 7.5
CVE-2015-6823 [HIGH] CVE-2015-6823: The allocate_buffers function in libavcodec/alac
The allocate_buffers function in libavcodec/alac.c in FFmpeg before 2.7.2 does not initialize certain context data, which allows remote attackers to cause a denial of service (segmentation violation) or possibly have unspecified other impact via crafted Apple Lossless Audio Codec (ALAC) data.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://ffmpeg.org/security.htmlhttp://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=f7068bf277a37479aecde2832208d820682b35e6http://www.securitytracker.com/id/1033483https://lists.debian.org/debian-lts-announce/2018/12/msg00010.htmlhttp://ffmpeg.org/security.htmlhttp://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=f7068bf277a37479aecde2832208d820682b35e6http://www.securitytracker.com/id/1033483https://lists.debian.org/debian-lts-announce/2018/12/msg00010.html
2015-09-06
Published