Lucene search

K
cve[email protected]CVE-2014-9318
HistoryDec 09, 2014 - 11:59 p.m.

CVE-2014-9318

2014-12-0923:59:17
CWE-119
web.nvd.nist.gov
26
cve-2014-9318
ffmpeg
denial of service
out-of-bounds heap access
nvd
security vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.8 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

77.7%

The raw_decode function in libavcodec/rawdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap access) and possibly have other unspecified impact via a crafted .cine file that triggers the avpicture_get_size function to return a negative frame size.

Affected configurations

NVD
Node
ffmpegffmpegRange2.1.5
OR
ffmpegffmpegMatch2.2
OR
ffmpegffmpegMatch2.2.4
OR
ffmpegffmpegMatch2.3
OR
ffmpegffmpegMatch2.3.2
OR
ffmpegffmpegMatch2.3.3
OR
ffmpegffmpegMatch2.3.4
OR
ffmpegffmpegMatch2.3.5
OR
ffmpegffmpegMatch2.4
OR
ffmpegffmpegMatch2.4.1
OR
ffmpegffmpegMatch2.4.2
OR
ffmpegffmpegMatch2.4.3

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.8 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

77.7%