Lucene search

K
ubuntucveUbuntu.comUB:CVE-2017-14057
HistoryAug 31, 2017 - 12:00 a.m.

CVE-2017-14057

2017-08-3100:00:00
ubuntu.com
ubuntu.com
15

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

57.6%

In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of
File) check might cause huge CPU and memory consumption. When a crafted ASF
file, which claims a large “name_len” or “count” field in the header but
does not contain sufficient backing data, is provided, the loops over the
name and markers would consume huge CPU and memory resources, since there
is no EOF check inside these loops.

OSVersionArchitecturePackageVersionFilename
ubuntu16.04noarchffmpeg< 7:2.8.14-0ubuntu0.16.04.1UNKNOWN

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

57.6%