Assertion violation in FFmpeg - CVE-2018-12458
Published: July 23, 2018 / Updated: July 26, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c. A remote attacker can supply specially crafted AVI file to MPEG4, trick the victim into converting it, trigger assertion violation and cause the service to crash.
Affected software
Debian Linux
ffmpeg (Alpine package)
How to mitigate CVE-2018-12458
ffmpeg (Alpine package) - update to 3.4.4-r0