PT-2026-64154 · FFmpeg+3 · Ffmpeg+3
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions 2.7 through 8.1.2
Description
An out-of-bounds write issue exists in the TDSC video decoder. A remote attacker can cause heap corruption by providing a specially crafted AVI file that alters frame dimensions across TDSF frames. The
tdsc parse tdsf() function does not unreference the current reference frame before calling av frame get buffer(). This leads the tdsc blit() and tdsc yuv2rgb() functions to write attacker-controlled pixel data beyond the boundaries of the undersized reference frame buffer, which can result in a process crash or potential arbitrary code execution.Recommendations
Update FFmpeg to a version later than 8.1.2.
Exploit
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ffmpeg
Linuxmint
Red Os
Ubuntu