Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4989
HistorySep 04, 2017 - 2:29 a.m.

Denial Of Service (DoS) Via High CPU And Memory Consumption

2017-09-0402:29:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.002

Percentile

57.6%

FFmpeg is vulnerable to denial of service (DoS) attacks. These attacks are possible because FFmpeg does not check for an EOF (End of File) in the asf_read_marker() function. This leads to high CPU and memory consumption when a malicious ASF file with a large name_len or count field in the header but without sufficient backing data is input.