CVE-2018-9841
published 2018-04-07CVE-2018-9841: The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out-of-array access) or…
PriorityP337high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.76%
75.7th percentile
The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via a long filename.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:3.4.3-1 (bookworm) | ffmpeg 7:3.4.3-1 (bookworm) |
| ffmpeg | ffmpeg | <= 3.4.2 | — |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.3-1 | 7:3.4.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.3-1 | 7:3.4.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.3-1 | 7:3.4.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.3-1 | 7:3.4.3-1 |
| klibc_project | klibc | >= 0 < 2.0.7-1ubuntu5.2 | 2.0.7-1ubuntu5.2 |
| klibc_project | klibc | >= 0 < 2.0.10-4ubuntu0.1 | 2.0.10-4ubuntu0.1 |
| klibc_project | klibc | >= 0 < 2.0.13-4ubuntu0.1 | 2.0.13-4ubuntu0.1 |
| klibc_project | klibc | >= 0 < 2.0.3-0ubuntu1.14.04.3+esm3 | 2.0.3-0ubuntu1.14.04.3+esm3 |
| klibc_project | klibc | >= 0 < 2.0.4-8ubuntu1.16.04.4+esm2 | 2.0.4-8ubuntu1.16.04.4+esm2 |
| klibc_project | klibc | >= 0 < 2.0.4-9ubuntu2.2+esm1 | 2.0.4-9ubuntu2.2+esm1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2018-9841: ffmpeg - The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows...
vendor_debian·2018·CVSS 8.8
CVE-2018-9841 [HIGH] CVE-2018-9841: ffmpeg - The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows...
The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via a long filename.
Scope: local
bookworm: resolved (fixed in 7:3.4.3-1)
bullseye: resolved (fixed in 7:3.4.3-1)
forky: resolved (fixed in 7:3.4.3-1)
sid: resolved (fixed in 7:3.4.3-1)
trixie: resolved (fixed in 7:3.4.3-1)
OSV
klibc vulnerabilities
osv·2024-05-23·CVSS 8.8
CVE-2016-9840 klibc vulnerabilities
klibc vulnerabilities
USN-6736-1 fixed vulnerabilities in klibc. This update provides the
corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate operations. An attacker could use
this issue to cause klibc to c
OSV
klibc vulnerabilities
osv·2024-04-16·CVSS 8.8
CVE-2016-9840 klibc vulnerabilities
klibc vulnerabilities
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2022-37434)
GHSA
GHSA-pch3-qm5g-746r: The export function in libavfilter/vf_signature
ghsa_unreviewed·2022-05-13
CVE-2018-9841 [HIGH] CWE-125 GHSA-pch3-qm5g-746r: The export function in libavfilter/vf_signature
The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via a long filename.
OSV
CVE-2018-9841: The export function in libavfilter/vf_signature
osv·2018-04-07·CVSS 8.8
CVE-2018-9841 [HIGH] CVE-2018-9841: The export function in libavfilter/vf_signature
The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via a long filename.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-04-07
Published