Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-9603
HistoryJan 16, 2015 - 12:00 a.m.

CVE-2014-9603

2015-01-1600:00:00
ubuntu.com
ubuntu.com
5

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.004 Low

EPSS

Percentile

72.1%

The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2
does not validate the relationship between a certain length value and the
frame width, which allows remote attackers to cause a denial of service
(out-of-bounds array access) or possibly have unspecified other impact via
crafted Sierra VMD video data.

Bugs

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.004 Low

EPSS

Percentile

72.1%