SB2017070110 - Buffer overflow in FFmpeg
Published: July 1, 2017 Updated: June 8, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2015-3395)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via a crafted image, related to a pixel pointer, which triggers an out-of-bounds array access.
Remediation
Install update from vendor's website.
References
- http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=f7e1367f58263593e6cee3c282f7277d7ee9d553
- http://www.debian.org/security/2015/dsa-3288
- http://www.securityfocus.com/bid/74433
- http://www.ubuntu.com/usn/USN-2944-1
- https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.4
- https://security.gentoo.org/glsa/201603-06
- https://security.gentoo.org/glsa/201705-08
- https://www.ffmpeg.org/security.html