Out-of-bounds read in FFmpeg - CVE-2018-10001
Published: July 26, 2018
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to cause DoS condition.
The vulnerability exists in the decode_init function in libavcodec/utvideodec.c due to insufficient input validation. A remote attacker can trick the victim into opening a specially crafted AVI file that submits malicious input, trigger a out-of-bounds read and cause the service to crash.
Affected software
Debian Linux
Gentoo Linux
ffmpeg (Alpine package)
How to mitigate CVE-2018-10001
ffmpeg (Alpine package) - update to 3.4.4-r0