CVE-2022-3965
published 2022-11-13CVE-2022-3965: A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream of the file libavcodec/smcenc.c of the…
PriorityP338high8.1CVSS 3.1
AVNACLPRNUIRSUCHINAH
EPSS
0.88%
55.3th percentile
A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream of the file libavcodec/smcenc.c of the component QuickTime Graphics Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. The attack can be initiated remotely. The name of the patch is 13c13109759090b7f7182480d075e13b36ed8edd. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213544.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:5.1.3-1 (bookworm) | ffmpeg 7:5.1.3-1 (bookworm) |
| ffmpeg | ffmpeg | >= 0 < 7:5.1.3-1 | 7:5.1.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:5.1.3-1 | 7:5.1.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:5.1.3-1 | 7:5.1.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.8.17-0ubuntu0.1+esm5 | 7:2.8.17-0ubuntu0.1+esm5 |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.11-0ubuntu0.1+esm1 | 7:3.4.11-0ubuntu0.1+esm1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.2.7-0ubuntu0.1+esm1 | 7:4.2.7-0ubuntu0.1+esm1 |
| ffmpeg | ffmpeg | >= 0 < 7:4.4.2-0ubuntu0.22.04.1+esm1 | 7:4.4.2-0ubuntu0.22.04.1+esm1 |
| ffmpeg | ffmpeg | >= 5.0 < 5.0.3 | 5.0.3 |
| ffmpeg | ffmpeg | >= 5.1 < 5.1.3 | 5.1.3 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv8.1HIGH
vendor_ubuntu7.5HIGH
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ffmpeg vulnerabilities
osv·2023-03-16·CVSS 7.5
CVE-2022-3109 [HIGH] ffmpeg vulnerabilities
ffmpeg vulnerabilities
It was discovered that FFmpeg could be made to dereference a null
pointer. An attacker could possibly use this to cause a denial of
service via application crash. These issues only affected Ubuntu
16.04 ESM, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. (CVE-2022-3109, CVE-2022-3341)
It was discovered that FFmpeg could be made to access an out-of-bounds
frame by the Apple RPZA encoder. An attacker could possibly use this
to cause a denial of service via application crash or access sensitive
information. This issue only affected Ubuntu 22.04 LTS and Ubuntu
22.10. (CVE-2022-3964)
It was discovered that FFmpeg could be made to access an out-of-bounds
frame by the QuickTime encoder. An attacker could possibly use this to
cause a denial of service via applic
GHSA
GHSA-pv63-r3vq-5qmc: A vulnerability classified as problematic was found in ffmpeg
ghsa_unreviewed·2022-11-13
CVE-2022-3965 [HIGH] CWE-119 GHSA-pv63-r3vq-5qmc: A vulnerability classified as problematic was found in ffmpeg
A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream of the file libavcodec/smcenc.c of the component QuickTime Graphics Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. The attack can be initiated remotely. The name of the patch is 13c13109759090b7f7182480d075e13b36ed8edd. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213544.
OSV
CVE-2022-3965: A vulnerability classified as problematic was found in ffmpeg
osv·2022-11-13·CVSS 8.1
CVE-2022-3965 [HIGH] CVE-2022-3965: A vulnerability classified as problematic was found in ffmpeg
A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream of the file libavcodec/smcenc.c of the component QuickTime Graphics Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. The attack can be initiated remotely. The name of the patch is 13c13109759090b7f7182480d075e13b36ed8edd. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213544.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2023-03-16·CVSS 7.5
CVE-2022-3341 [HIGH] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: Several security issues were fixed in FFmpeg.
It was discovered that FFmpeg could be made to dereference a null
pointer. An attacker could possibly use this to cause a denial of
service via application crash. These issues only affected Ubuntu
16.04 ESM, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. (CVE-2022-3109, CVE-2022-3341)
It was discovered that FFmpeg could be made to access an out-of-bounds
frame by the Apple RPZA encoder. An attacker could possibly use this
to cause a denial of service via application crash or access sensitive
information. This issue only affected Ubuntu 22.04 LTS and Ubuntu
22.10. (CVE-2022-3964)
It was discovered that FFmpeg could be made to access an out-of-bounds
frame by the QuickTime encoder. An attacker
Debian
CVE-2022-3965: ffmpeg - A vulnerability classified as problematic was found in ffmpeg. This vulnerabilit...
vendor_debian·2022·CVSS 4.3
CVE-2022-3965 [MEDIUM] CVE-2022-3965: ffmpeg - A vulnerability classified as problematic was found in ffmpeg. This vulnerabilit...
A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream of the file libavcodec/smcenc.c of the component QuickTime Graphics Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. The attack can be initiated remotely. The name of the patch is 13c13109759090b7f7182480d075e13b36ed8edd. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213544.
Scope: local
bookworm: resolved (fixed in 7:5.1.3-1)
bullseye: resolved
forky: resolved (fixed in 7:5.1.3-1)
sid: resolved (fixed in 7:5.1.3-1)
trixie: resolved (fixed in 7:5.1.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/13c13109759090b7f7182480d075e13b36ed8eddhttps://security.gentoo.org/glsa/202312-14https://vuldb.com/?id.213544https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/13c13109759090b7f7182480d075e13b36ed8eddhttps://security.gentoo.org/glsa/202312-14https://vuldb.com/?id.213544
2022-11-13
Published