CVE-2018-1999012Infinite Loop in Ffmpeg

CWE-835Infinite Loop4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.5%
top 33.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 23
Latest updateMay 13

Description

FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835: Infinite loop vulnerability in pva format demuxer that can result in a Vulnerability that allows attackers to consume excessive amount of resources like CPU and RAM. This attack appear to be exploitable via specially crafted PVA file has to be provided as input. This vulnerability appears to have been fixed in 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 and later.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/ffmpeg< ffmpeg 7:4.0.2-1 (bookworm)
Debianffmpeg/ffmpeg< 7:4.0.2-1+3
NVDffmpeg/ffmpeg4.0.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pvhq-7xgc-xmjm: FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835: Infinite loop vulnerability in pva format demuxer that can result in2022-05-13
OSV
CVE-2018-1999012: FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835: Infinite loop vulnerability in pva format demuxer that can result in2018-07-23

📋Vendor Advisories

1
Debian
CVE-2018-1999012: ffmpeg - FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835...2018