CVE-2019-12730
published 2019-06-04CVE-2019-12730: aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of…
PriorityP344critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.03%
86.1th percentile
aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:4.1.4-1 (bookworm) | ffmpeg 7:4.1.4-1 (bookworm) |
| ffmpeg | ffmpeg | < 3.2.14 | 3.2.14 |
| ffmpeg | ffmpeg | >= 0 < 7:4.1.4-1 | 7:4.1.4-1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.1.4-1 | 7:4.1.4-1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.1.4-1 | 7:4.1.4-1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.1.4-1 | 7:4.1.4-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.8.17-0ubuntu0.1 | 7:2.8.17-0ubuntu0.1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.8-0ubuntu0.2 | 7:3.4.8-0ubuntu0.2 |
| ffmpeg | ffmpeg | >= 0 < 7:4.2.4-1ubuntu0.1 | 7:4.2.4-1ubuntu0.1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2020-07-22·CVSS 7.5
CVE-2018-15822 [HIGH] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: Several security issues were fixed in FFmpeg.
It was discovered that FFmpeg incorrectly verified empty audio packets or
HEVC data. An attacker could possibly use this issue to cause a denial of
service via a crafted file. This issue only affected Ubuntu 16.04 LTS, as
it was already fixed in Ubuntu 18.04 LTS. For more information see:
https://usn.ubuntu.com/usn/usn-3967-1
(CVE-2018-15822, CVE-2019-11338)
It was discovered that FFmpeg incorrectly handled sscanf failures. An
attacker could possibly use this issue to cause a denial of service or
other unspecified impact. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2019-12730)
It was discovered that FFmpeg incorrectly handled certain WEBM files. An
attacker could possibly use t
Debian
CVE-2019-12730: ffmpeg - aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1...
vendor_debian·2019·CVSS 9.8
CVE-2019-12730 [CRITICAL] CVE-2019-12730: ffmpeg - aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1...
aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
Scope: local
bookworm: resolved (fixed in 7:4.1.4-1)
bullseye: resolved (fixed in 7:4.1.4-1)
forky: resolved (fixed in 7:4.1.4-1)
sid: resolved (fixed in 7:4.1.4-1)
trixie: resolved (fixed in 7:4.1.4-1)
GHSA
GHSA-qvcr-p33x-3v45: aa_read_header in libavformat/aadec
ghsa_unreviewed·2022-05-24
CVE-2019-12730 [CRITICAL] GHSA-qvcr-p33x-3v45: aa_read_header in libavformat/aadec
aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 does not check for sscanf failure and consequently allows use of uninitialized variables.
OSV
ffmpeg vulnerabilities
osv·2020-07-22·CVSS 7.5
CVE-2018-15822 [HIGH] ffmpeg vulnerabilities
ffmpeg vulnerabilities
It was discovered that FFmpeg incorrectly verified empty audio packets or
HEVC data. An attacker could possibly use this issue to cause a denial of
service via a crafted file. This issue only affected Ubuntu 16.04 LTS, as
it was already fixed in Ubuntu 18.04 LTS. For more information see:
https://usn.ubuntu.com/usn/usn-3967-1
(CVE-2018-15822, CVE-2019-11338)
It was discovered that FFmpeg incorrectly handled sscanf failures. An
attacker could possibly use this issue to cause a denial of service or
other unspecified impact. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2019-12730)
It was discovered that FFmpeg incorrectly handled certain WEBM files. An
attacker could possibly use this issue to obtain sensitive data or other
unspecified impact.
OSV
CVE-2019-12730: aa_read_header in libavformat/aadec
osv·2019-06-04·CVSS 9.8
CVE-2019-12730 [CRITICAL] CVE-2019-12730: aa_read_header in libavformat/aadec
aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/109317https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/9b4004c054964a49c7ba44583f4cee22486dd8f2https://git.ffmpeg.org/gitweb/ffmpeg.git/shortlog/n4.1.4https://github.com/FFmpeg/FFmpeg/commit/ed188f6dcdf0935c939ed813cf8745d50742014bhttps://github.com/FFmpeg/FFmpeg/compare/a97ea53...ba11e40https://seclists.org/bugtraq/2019/Aug/30https://security.gentoo.org/glsa/202003-65https://usn.ubuntu.com/4431-1/https://www.debian.org/security/2019/dsa-4502http://www.securityfocus.com/bid/109317https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/9b4004c054964a49c7ba44583f4cee22486dd8f2https://git.ffmpeg.org/gitweb/ffmpeg.git/shortlog/n4.1.4https://github.com/FFmpeg/FFmpeg/commit/ed188f6dcdf0935c939ed813cf8745d50742014bhttps://github.com/FFmpeg/FFmpeg/compare/a97ea53...ba11e40https://seclists.org/bugtraq/2019/Aug/30https://security.gentoo.org/glsa/202003-65https://usn.ubuntu.com/4431-1/https://www.debian.org/security/2019/dsa-4502
2019-06-04
Published