CVE-2018-1999013
published 2018-07-23CVE-2018-1999013: FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability…
PriorityP433medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
EPSS
1.77%
75.8th percentile
FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to be exploitable via specially crafted RM file has to be provided as input. This vulnerability appears to have been fixed in a7e032a277452366771951e29fd0bf2bd5c029f0 and later.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:4.0.2-1 (bookworm) | ffmpeg 7:4.0.2-1 (bookworm) |
| ffmpeg | ffmpeg | <= 4.0.1 | — |
| ffmpeg | ffmpeg | >= 0 < 7:4.0.2-1 | 7:4.0.2-1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.0.2-1 | 7:4.0.2-1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.0.2-1 | 7:4.0.2-1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.0.2-1 | 7:4.0.2-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-74ff-r9q5-73vp: FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vuln
ghsa_unreviewed·2022-05-14
CVE-2018-1999013 [MEDIUM] CWE-416 GHSA-74ff-r9q5-73vp: FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vuln
FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to be exploitable via specially crafted RM file has to be provided as input. This vulnerability appears to have been fixed in a7e032a277452366771951e29fd0bf2bd5c029f0 and later.
OSV
CVE-2018-1999013: FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vuln
osv·2018-07-23·CVSS 6.5
CVE-2018-1999013 [MEDIUM] CVE-2018-1999013: FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vuln
FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to be exploitable via specially crafted RM file has to be provided as input. This vulnerability appears to have been fixed in a7e032a277452366771951e29fd0bf2bd5c029f0 and later.
Debian
CVE-2018-1999013: ffmpeg - FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-aft...
vendor_debian·2018·CVSS 6.5
CVE-2018-1999013 [MEDIUM] CVE-2018-1999013: ffmpeg - FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-aft...
FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to be exploitable via specially crafted RM file has to be provided as input. This vulnerability appears to have been fixed in a7e032a277452366771951e29fd0bf2bd5c029f0 and later.
Scope: local
bookworm: resolved (fixed in 7:4.0.2-1)
bullseye: resolved (fixed in 7:4.0.2-1)
forky: resolved (fixed in 7:4.0.2-1)
sid: resolved (fixed in 7:4.0.2-1)
trixie: resolved (fixed in 7:4.0.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-07-23
Published