CVE-2017-14170
published 2017-09-07CVE-2017-14170: In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File) check might cause huge CPU…
PriorityP428medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
1.77%
75.8th percentile
In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted MXF file, which claims a large "nb_index_entries" field in the header but does not contain sufficient backing data, is provided, the loop would consume huge CPU resources, since there is no EOF check inside the loop. Moreover, this big loop can be invoked multiple times if there is more than one applicable data segment in the crafted MXF file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:3.3.4-1 (bookworm) | ffmpeg 7:3.3.4-1 (bookworm) |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:3.3.4-1 | 7:3.3.4-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.3.4-1 | 7:3.3.4-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.3.4-1 | 7:3.3.4-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.3.4-1 | 7:3.3.4-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xv94-736p-6866: In libavformat/mxfdec
ghsa_unreviewed·2022-05-13
CVE-2017-14170 [HIGH] CWE-834 GHSA-xv94-736p-6866: In libavformat/mxfdec
In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted MXF file, which claims a large "nb_index_entries" field in the header but does not contain sufficient backing data, is provided, the loop would consume huge CPU resources, since there is no EOF check inside the loop. Moreover, this big loop can be invoked multiple times if there is more than one applicable data segment in the crafted MXF file.
OSV
CVE-2017-14170: In libavformat/mxfdec
osv·2017-09-07·CVSS 6.5
CVE-2017-14170 [MEDIUM] CVE-2017-14170: In libavformat/mxfdec
In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted MXF file, which claims a large "nb_index_entries" field in the header but does not contain sufficient backing data, is provided, the loop would consume huge CPU resources, since there is no EOF check inside the loop. Moreover, this big loop can be invoked multiple times if there is more than one applicable data segment in the crafted MXF file.
Debian
CVE-2017-14170: ffmpeg - In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_ar...
vendor_debian·2017·CVSS 6.5
CVE-2017-14170 [MEDIUM] CVE-2017-14170: ffmpeg - In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_ar...
In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted MXF file, which claims a large "nb_index_entries" field in the header but does not contain sufficient backing data, is provided, the loop would consume huge CPU resources, since there is no EOF check inside the loop. Moreover, this big loop can be invoked multiple times if there is more than one applicable data segment in the crafted MXF file.
Scope: local
bookworm: resolved (fixed in 7:3.3.4-1)
bullseye: resolved (fixed in 7:3.3.4-1)
forky: resolved (fixed in 7:3.3.4-1)
sid: resolved (fixed in 7:3.3.4-1)
trixie: resolved (fixed in 7:3.3.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.debian.org/security/2017/dsa-3996http://www.securityfocus.com/bid/100700https://github.com/FFmpeg/FFmpeg/commit/900f39692ca0337a98a7cf047e4e2611071810c2https://github.com/FFmpeg/FFmpeg/commit/f173cdfe669556aa92857adafe60cbe5f2aa1210https://lists.debian.org/debian-lts-announce/2019/01/msg00006.htmlhttp://www.debian.org/security/2017/dsa-3996http://www.securityfocus.com/bid/100700https://github.com/FFmpeg/FFmpeg/commit/900f39692ca0337a98a7cf047e4e2611071810c2https://github.com/FFmpeg/FFmpeg/commit/f173cdfe669556aa92857adafe60cbe5f2aa1210https://lists.debian.org/debian-lts-announce/2019/01/msg00006.html
2017-09-07
Published