CVE-2017-14057
published 2017-08-31CVE-2017-14057: In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file…
PriorityP427medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
1.81%
76.3th percentile
In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file, which claims a large "name_len" or "count" field in the header but does not contain sufficient backing data, is provided, the loops over the name and markers would consume huge CPU and memory resources, since there is no EOF check inside these loops.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:3.3.4-1 (bookworm) | ffmpeg 7:3.3.4-1 (bookworm) |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:3.3.4-1 | 7:3.3.4-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.3.4-1 | 7:3.3.4-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.3.4-1 | 7:3.3.4-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.3.4-1 | 7:3.3.4-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-14057: ffmpeg - In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) ...
vendor_debian·2017·CVSS 6.5
CVE-2017-14057 [MEDIUM] CVE-2017-14057: ffmpeg - In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) ...
In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file, which claims a large "name_len" or "count" field in the header but does not contain sufficient backing data, is provided, the loops over the name and markers would consume huge CPU and memory resources, since there is no EOF check inside these loops.
Scope: local
bookworm: resolved (fixed in 7:3.3.4-1)
bullseye: resolved (fixed in 7:3.3.4-1)
forky: resolved (fixed in 7:3.3.4-1)
sid: resolved (fixed in 7:3.3.4-1)
trixie: resolved (fixed in 7:3.3.4-1)
GHSA
GHSA-vwrx-gcwc-3w8c: In FFmpeg 3
ghsa_unreviewed·2022-05-13
CVE-2017-14057 [HIGH] CWE-834 GHSA-vwrx-gcwc-3w8c: In FFmpeg 3
In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file, which claims a large "name_len" or "count" field in the header but does not contain sufficient backing data, is provided, the loops over the name and markers would consume huge CPU and memory resources, since there is no EOF check inside these loops.
OSV
CVE-2017-14057: In FFmpeg 3
osv·2017-08-31·CVSS 6.5
CVE-2017-14057 [MEDIUM] CVE-2017-14057: In FFmpeg 3
In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file, which claims a large "name_len" or "count" field in the header but does not contain sufficient backing data, is provided, the loops over the name and markers would consume huge CPU and memory resources, since there is no EOF check inside these loops.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.debian.org/security/2017/dsa-3996http://www.securityfocus.com/bid/100630https://github.com/FFmpeg/FFmpeg/commit/7f9ec5593e04827249e7aeb466da06a98a0d7329https://lists.debian.org/debian-lts-announce/2019/01/msg00006.htmlhttp://www.debian.org/security/2017/dsa-3996http://www.securityfocus.com/bid/100630https://github.com/FFmpeg/FFmpeg/commit/7f9ec5593e04827249e7aeb466da06a98a0d7329https://lists.debian.org/debian-lts-announce/2019/01/msg00006.html
2017-08-31
Published