FFmpeg 'libavfilter/vf_transpose.c' Denial of Service Vulnerability (CVE-2018-6392)
FFmpeg 'libavfilter/vf_transpose.c' Denial of Service Vulnerability (CVE-2018-6392)
Release date:
Updated on:
Affected Systems:
FFmpeg
Unaffected system:
FFmpeg <= 3.4.1
Description:
Bugtraq id: 102848
CVE (CAN) ID: CVE-2018-6392
FFmpeg is a free software that allows you to perform video, transfer, and stream functions in multiple formats of audio and video.
In FFmpeg 3.4.1 and earlier versions, the libavfilter/vf_transpose.c/filter_slice function has a security vulnerability. A remote attacker can exploit this vulnerability to cause denial-of-service (DoS) attacks by constructing mp4 files.
<* Source: vendor
*>
Suggestion:
Vendor patch:
FFmpeg
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/3f621455d62e46745453568d915badd5b1e5bcd5
Https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/c6939f65a116b1ffed345d29d8621ee4ffb32235
Http://www.ffmpeg.org/