CVE-2015-8364
published 2015-11-26CVE-2015-8364: Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote…
PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.07%
79.4th percentile
Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via crafted image dimensions in Indeo Video Interactive data.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | ffmpeg | < ffmpeg 7:2.8.3-1 (bookworm) | ffmpeg 7:2.8.3-1 (bookworm) |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:2.8.3-1 | 7:2.8.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.8.3-1 | 7:2.8.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.8.3-1 | 7:2.8.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.8.3-1 | 7:2.8.3-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libav vulnerabilities
vendor_ubuntu·2016-04-04
CVE-2014-8541 Libav vulnerabilities
Title: Libav vulnerabilities
Summary: Libav could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that Libav incorrectly handled certain malformed media
files. If a user were tricked into opening a crafted media file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2015-8364: ffmpeg - Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpe...
vendor_debian·2015·CVSS 6.8
CVE-2015-8364 [MEDIUM] CVE-2015-8364: ffmpeg - Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpe...
Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via crafted image dimensions in Indeo Video Interactive data.
Scope: local
bookworm: resolved (fixed in 7:2.8.3-1)
bullseye: resolved (fixed in 7:2.8.3-1)
forky: resolved (fixed in 7:2.8.3-1)
sid: resolved (fixed in 7:2.8.3-1)
trixie: resolved (fixed in 7:2.8.3-1)
GHSA
GHSA-r2h9-33j6-9q9f: Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi
ghsa_unreviewed·2022-05-14
CVE-2015-8364 [MEDIUM] GHSA-r2h9-33j6-9q9f: Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi
Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via crafted image dimensions in Indeo Video Interactive data.
OSV
CVE-2015-8364: Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi
osv·2015-11-26·CVSS 6.8
CVE-2015-8364 [MEDIUM] CVE-2015-8364: Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi
Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via crafted image dimensions in Indeo Video Interactive data.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=df91aa034b82b77a3c4e01791f4a2b2ff6c82066http://lists.opensuse.org/opensuse-updates/2015-12/msg00118.htmlhttp://www.ubuntu.com/usn/USN-2944-1https://lists.debian.org/debian-lts-announce/2018/12/msg00009.htmlhttp://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=df91aa034b82b77a3c4e01791f4a2b2ff6c82066http://lists.opensuse.org/opensuse-updates/2015-12/msg00118.htmlhttp://www.ubuntu.com/usn/USN-2944-1https://lists.debian.org/debian-lts-announce/2018/12/msg00009.html
2015-11-26
Published