CVE-2019-11338

Severity
8.8HIGH
EPSS
2.0%
top 16.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 19
Latest updateMay 24

Description

libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

Debianffmpeg< 7:4.1.3-1+3
Ubuntuffmpeg< 7:2.8.17-0ubuntu0.1+2
NVDffmpeg/ffmpeg3.4, 4.1.2+1

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 16.04, 18.04, 18.10, 19.04, 20.04

Patches

🔴Vulnerability Details

4
GHSA
GHSA-96rf-5r43-949p: libavcodec/hevcdec2022-05-24
OSV
ffmpeg vulnerabilities2020-07-22
OSV
CVE-2019-11338: libavcodec/hevcdec2019-04-19
CVEList
CVE-2019-11338: libavcodec/hevcdec2019-04-18

📋Vendor Advisories

3
Ubuntu
FFmpeg vulnerabilities2020-07-22
Ubuntu
FFmpeg vulnerabilities2019-05-06
Debian
CVE-2019-11338: ffmpeg - libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate f...2019
CVE-2019-11338 (HIGH CVSS 8.8) | libavcodec/hevcdec.c in FFmpeg 3.4 | cvebase.io