PT-2018-3402 · FFmpeg+4 · Ffmpeg+4
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
FFmpeg versions through 2.8
Description:
The issue is related to the
flv write packet function in the FFmpeg library, which lacks a check for an empty audio packet. This can lead to an assertion failure. Exploitation of this issue may allow a remote attacker to cause a denial of service.Recommendations:
For FFmpeg versions through 2.8, consider updating to a version that includes a fix for this issue, as the current version may allow for a denial of service attack due to the lack of checking for empty audio packets in the
flv write packet function.Correção
RCE
Assertion Failure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Ffmpeg
Linuxmint
Suse
Ubuntu