Out-of-bounds read in FFmpeg - CVE-2018-13300
Published: July 26, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to improper argument (AVCodecParameters) passed to the avpriv_request_sample function in the handle_eac3 function in libavformat/movenc.c. A remote attacker can supply specially crafted AVI file to MPEG4, trick the victim into converting it, trigger out-of-bounds read and cause the service to crash or possibly access arbitrary data
Affected software
SUSE Package Hub for SUSE Linux Enterprise
Debian Linux
SUSE Linux
Opensuse
ffmpeg (Alpine package)
How to mitigate CVE-2018-13300
ffmpeg (Alpine package) - update to 3.4.4-r0