Out-of-bounds read in FFmpeg - CVE-2018-7557

 

Out-of-bounds read in FFmpeg - CVE-2018-7557

Published: March 28, 2018


Vulnerability identifier: #VU11307
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7557
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the decode_init function due to out-of-bounds read. A remote attacker can trick the victim into opening a specially crafted Audio Video Interleave (AVI) file with the affected application, trigger memory corruption and cause the service to crash.

Affected software

FFmpeg
Gentoo Linux
ffmpeg (Alpine package)

How to mitigate CVE-2018-7557

Install update from vendor's website.

ffmpeg (Alpine package) - update to 3.4.4-r0

External References

Related Security Bulletins