CVE-2019-11339
published 2019-04-19CVE-2019-11339: The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote attackers to cause a denial of service…
PriorityP339high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.75%
84.7th percentile
The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via crafted MPEG-4 video data.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:4.1.3-1 (bookworm) | ffmpeg 7:4.1.3-1 (bookworm) |
| ffmpeg | ffmpeg | >= 0 < 7:4.1.3-1 | 7:4.1.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.1.3-1 | 7:4.1.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.1.3-1 | 7:4.1.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.1.3-1 | 7:4.1.3-1 |
| ffmpeg | ffmpeg | >= 4.0 < 4.0.4 | 4.0.4 |
| ffmpeg | ffmpeg | >= 4.1 < 4.1.2 | 4.1.2 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2019-05-06
CVE-2018-15822 FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: FFmpeg could be made to crash if it opened a specially crafted
file.
It was discovered that FFmpeg contained multiple security issues when handling
certain multimedia files. If a user were tricked into opening a crafted
multimedia file, an attacker could cause a denial of service via application
crash.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-11339: ffmpeg - The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4....
vendor_debian·2019·CVSS 8.8
CVE-2019-11339 [HIGH] CVE-2019-11339: ffmpeg - The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4....
The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via crafted MPEG-4 video data.
Scope: local
bookworm: resolved (fixed in 7:4.1.3-1)
bullseye: resolved (fixed in 7:4.1.3-1)
forky: resolved (fixed in 7:4.1.3-1)
sid: resolved (fixed in 7:4.1.3-1)
trixie: resolved (fixed in 7:4.1.3-1)
GHSA
GHSA-x227-wfq2-5jxp: The studio profile decoder in libavcodec/mpeg4videodec
ghsa_unreviewed·2022-05-24
CVE-2019-11339 [HIGH] CWE-125 GHSA-x227-wfq2-5jxp: The studio profile decoder in libavcodec/mpeg4videodec
The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via crafted MPEG-4 video data.
OSV
CVE-2019-11339: The studio profile decoder in libavcodec/mpeg4videodec
osv·2019-04-19·CVSS 8.8
CVE-2019-11339 [HIGH] CVE-2019-11339: The studio profile decoder in libavcodec/mpeg4videodec
The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via crafted MPEG-4 video data.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00012.htmlhttp://www.securityfocus.com/bid/108037https://github.com/FFmpeg/FFmpeg/commit/1f686d023b95219db933394a7704ad9aa5f01cbbhttps://github.com/FFmpeg/FFmpeg/commit/d227ed5d598340e719eff7156b1aa0a4469e9a6ahttps://usn.ubuntu.com/3967-1/http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00012.htmlhttp://www.securityfocus.com/bid/108037https://github.com/FFmpeg/FFmpeg/commit/1f686d023b95219db933394a7704ad9aa5f01cbbhttps://github.com/FFmpeg/FFmpeg/commit/d227ed5d598340e719eff7156b1aa0a4469e9a6ahttps://usn.ubuntu.com/3967-1/
2019-04-19
Published