CVE-2018-1999014
published 2018-07-23CVE-2018-1999014: FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in DoS. This…
PriorityP430medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
1.47%
71.1th percentile
FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in DoS. This attack appear to be exploitable via specially crafted MXF file which has to be provided as input. This vulnerability appears to have been fixed in bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 and later.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:4.0.2-1 (bookworm) | ffmpeg 7:4.0.2-1 (bookworm) |
| ffmpeg | ffmpeg | <= 4.0.1 | — |
| ffmpeg | ffmpeg | >= 0 < 7:4.0.2-1 | 7:4.0.2-1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.0.2-1 | 7:4.0.2-1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.0.2-1 | 7:4.0.2-1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.0.2-1 | 7:4.0.2-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vw6x-3gg6-qxm3: FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in D
ghsa_unreviewed·2022-05-14
CVE-2018-1999014 [MEDIUM] CWE-125 GHSA-vw6x-3gg6-qxm3: FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in D
FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in DoS. This attack appear to be exploitable via specially crafted MXF file which has to be provided as input. This vulnerability appears to have been fixed in bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 and later.
OSV
CVE-2018-1999014: FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in D
osv·2018-07-23·CVSS 6.5
CVE-2018-1999014 [MEDIUM] CVE-2018-1999014: FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in D
FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in DoS. This attack appear to be exploitable via specially crafted MXF file which has to be provided as input. This vulnerability appears to have been fixed in bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 and later.
Debian
CVE-2018-1999014: ffmpeg - FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of...
vendor_debian·2018·CVSS 6.5
CVE-2018-1999014 [MEDIUM] CVE-2018-1999014: ffmpeg - FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of...
FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in DoS. This attack appear to be exploitable via specially crafted MXF file which has to be provided as input. This vulnerability appears to have been fixed in bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 and later.
Scope: local
bookworm: resolved (fixed in 7:4.0.2-1)
bullseye: resolved (fixed in 7:4.0.2-1)
forky: resolved (fixed in 7:4.0.2-1)
sid: resolved (fixed in 7:4.0.2-1)
trixie: resolved (fixed in 7:4.0.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-07-23
Published