PT-2026-78529 · FFmpeg+2 · Ffmpeg+2
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions prior to commit 65b0dab
Description
An out-of-bounds read exists in the DASH demuxer within
libavformat/dashdec.c. This occurs when a live DASH manifest is refreshed with a startNumber lower than the previous value, causing the current sequence number to become negative. Because the fragment retrieval function only verifies the upper bound before indexing the fragments array, a negative index can be used. A malicious or misconfigured DASH server can trigger this condition by providing a live manifest with a decreasing startNumber during a refresh.Recommendations
Update FFmpeg to the version containing commit 65b0dab or later.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ffmpeg
Linuxmint
Ubuntu