FFmpeg 'libavcodec/utvideodec. c' Denial of Service Vulnerability (CVE-2018-6621)
FFmpeg 'libavcodec/utvideodec. c' Denial of Service Vulnerability (CVE-2018-6621)
Release date:
Updated on:
Affected Systems:
FFmpeg <= 3.4.1
Description:
Bugtraq id: 102950
CVE (CAN) ID: CVE-2018-6621
FFmpeg is a free software that allows you to perform video, transfer, and stream functions in multiple formats of audio and video.
FFmpeg 3.4.1 and earlier versions, libavcodec/utvideodec. the c/decode_frame function has a security vulnerability in implementation, which allows remote attackers to exploit this vulnerability to cause Denial-of-Service (out-of-range read) Attacks by constructing AVI files ).
<* Source: vendor
*>
Suggestion:
Vendor patch:
FFmpeg
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/118e1b0b3370dd1c0da442901b486689efd1654b
Http://www.ffmpeg.org/