CVE-2022-3341
published 2023-01-12CVE-2022-3341: A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function…
PriorityP422medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.82%
53.4th percentile
A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and triggers the null pointer dereference error, causing an application to crash.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | ffmpeg | < ffmpeg 7:5.1-1 (bookworm) | ffmpeg 7:5.1-1 (bookworm) |
| ffmpeg | ffmpeg | < 5.0.3 | 5.0.3 |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:4.3.6-0+deb11u1 | 7:4.3.6-0+deb11u1 |
| ffmpeg | ffmpeg | >= 0 < 7:5.1-1 | 7:5.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:5.1-1 | 7:5.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:5.1-1 | 7:5.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.8.17-0ubuntu0.1+esm5 | 7:2.8.17-0ubuntu0.1+esm5 |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.11-0ubuntu0.1+esm1 | 7:3.4.11-0ubuntu0.1+esm1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.2.7-0ubuntu0.1+esm1 | 7:4.2.7-0ubuntu0.1+esm1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.4.2-0ubuntu0.22.04.1+esm1 | 7:4.4.2-0ubuntu0.22.04.1+esm1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ffmpeg vulnerabilities
osv·2023-03-16·CVSS 7.5
CVE-2022-3109 [HIGH] ffmpeg vulnerabilities
ffmpeg vulnerabilities
It was discovered that FFmpeg could be made to dereference a null
pointer. An attacker could possibly use this to cause a denial of
service via application crash. These issues only affected Ubuntu
16.04 ESM, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. (CVE-2022-3109, CVE-2022-3341)
It was discovered that FFmpeg could be made to access an out-of-bounds
frame by the Apple RPZA encoder. An attacker could possibly use this
to cause a denial of service via application crash or access sensitive
information. This issue only affected Ubuntu 22.04 LTS and Ubuntu
22.10. (CVE-2022-3964)
It was discovered that FFmpeg could be made to access an out-of-bounds
frame by the QuickTime encoder. An attacker could possibly use this to
cause a denial of service via applic
OSV
CVE-2022-3341: A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec
osv·2023-01-12·CVSS 5.3
CVE-2022-3341 [MEDIUM] CVE-2022-3341: A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec
A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and triggers the null pointer dereference error, causing an application to crash.
GHSA
GHSA-wp84-qf9p-3vp8: A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec
ghsa_unreviewed·2023-01-12
CVE-2022-3341 [MEDIUM] CWE-476 GHSA-wp84-qf9p-3vp8: A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec
A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and triggers the null pointer dereference error, causing an application to crash.
GHSA
Cross-site Scripting in Prism
ghsa·2022-02-22
CVE-2022-23647 [HIGH] CWE-79 Cross-site Scripting in Prism
Cross-site Scripting in Prism
### Impact
Prism's [Command line plugin](https://prismjs.com/plugins/command-line/) can be used by attackers to achieve an XSS attack. The Command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML code.
Server-side usage of Prism is not impacted. Websites that do not use the Command Line plugin are also not impacted.
### Patches
This bug has been fixed in v1.27.0.
### Workarounds
Do not use the Command line plugin on untrusted inputs, or sanitized all code blocks (remove all HTML code text) from all code blocks that use the Command line plugin.
### References
- https://github.com/PrismJS/prism/pull/3341
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2023-03-16·CVSS 7.5
CVE-2022-3341 [HIGH] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: Several security issues were fixed in FFmpeg.
It was discovered that FFmpeg could be made to dereference a null
pointer. An attacker could possibly use this to cause a denial of
service via application crash. These issues only affected Ubuntu
16.04 ESM, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. (CVE-2022-3109, CVE-2022-3341)
It was discovered that FFmpeg could be made to access an out-of-bounds
frame by the Apple RPZA encoder. An attacker could possibly use this
to cause a denial of service via application crash or access sensitive
information. This issue only affected Ubuntu 22.04 LTS and Ubuntu
22.10. (CVE-2022-3964)
It was discovered that FFmpeg could be made to access an out-of-bounds
frame by the QuickTime encoder. An attacker
Debian
CVE-2022-3341: ffmpeg - A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_heade...
vendor_debian·2022·CVSS 5.3
CVE-2022-3341 [MEDIUM] CVE-2022-3341: ffmpeg - A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_heade...
A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and triggers the null pointer dereference error, causing an application to crash.
Scope: local
bookworm: resolved (fixed in 7:5.1-1)
bullseye: resolved (fixed in 7:4.3.6-0+deb11u1)
forky: resolved (fixed in 7:5.1-1)
sid: resolved (fixed in 7:5.1-1)
trixie: resolved (fixed in 7:5.1-1)
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2157054https://github.com/FFmpeg/FFmpeg/commit/9cf652cef49d74afe3d454f27d49eb1a1394951ehttps://lists.debian.org/debian-lts-announce/2023/06/msg00016.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=2157054https://github.com/FFmpeg/FFmpeg/commit/9cf652cef49d74afe3d454f27d49eb1a1394951ehttps://lists.debian.org/debian-lts-announce/2023/06/msg00016.html
2023-01-12
Published