Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5376
HistoryNov 06, 2017 - 1:23 a.m.

Out-Of-Bounds Read

2017-11-0601:23:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.008 Low

EPSS

Percentile

81.2%

ffmpeg is vulnerable to out-of-bound reads. It happens because there is a discrepancy in the buf_size used to calculate “bytestream_end” and the “size” returned from the AV_RB24() function. A malicious user can pass a mp4 file to the system to trigger an out of array read.

CPENameOperatorVersion
ffmpegle2.8.3
ffmpeg-up-to-datele2.8.3