CVE-2017-9608NULL Pointer Dereference in Ffmpeg

Severity
6.5MEDIUMNVD
EPSS
8.9%
top 7.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 27
Latest updateMay 14

Description

The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted mov file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDffmpeg/ffmpeg3.33.3.3+1
debiandebian/ffmpeg< ffmpeg 7:3.3.3-1 (bookworm)
Debianffmpeg/ffmpeg< 7:3.3.3-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gj8f-pc7g-p9w6: The dnxhd decoder in FFmpeg before 32022-05-14
OSV
CVE-2017-9608: The dnxhd decoder in FFmpeg before 32017-12-27

📋Vendor Advisories

1
Debian
CVE-2017-9608: ffmpeg - The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote a...2017