Buffer overflow in FFmpeg - CVE-2015-3395

 

Buffer overflow in FFmpeg - CVE-2015-3395

Published: July 1, 2017 / Updated: June 8, 2025


Vulnerability identifier: #VU110590
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3395
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via a crafted image, related to a pixel pointer, which triggers an out-of-bounds array access.


Affected software

FFmpeg
Gentoo Linux
media-video/ffmpeg
media-video/libav

How to mitigate CVE-2015-3395

Install update from vendor's website.

FFmpeg - addressed in versions 2.0.7, 2.2.15, 2.4.8, 2.5.6, 2.6.2
media-video/ffmpeg - update to 2.6.3
media-video/libav - update to 11.8

External References

Related Security Bulletins