#VU14017 Assertion violation in FFmpeg - CVE-2018-12458
Published: July 23, 2018 / Updated: July 26, 2018
FFmpeg
ffmpeg.sourceforge.net
Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c. A remote attacker can supply specially crafted AVI file to MPEG4, trick the victim into converting it, trigger assertion violation and cause the service to crash.