CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
Percentile
89.3%
The decode_init function in kmvc.c in libavcodec in FFmpeg before 0.10 and
in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and
0.8.x before 0.8.1 allows remote attackers to cause a denial of service
(application crash) and possibly execute arbitrary code via a large palette
size in a KMVC encoded file.
Author | Note |
---|---|
mdeslaur | ffmpeg-extra in multiverse needs to have matching version libav-extra is built with tarball produced by libav package as of 2012-05-29, doesn’t seem to be fixed in libav 0.7 as of 2012-05-29, doesn’t seem to be fixed in ffmpeg 0.5.x |