NULL pointer dereference in FFmpeg - CVE-2017-9608
Published: December 27, 2017 / Updated: July 17, 2020
Vulnerability identifier: #VU31375
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2017-9608
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: ffmpeg.sourceforge.net
Affected software:
FFmpeg
FFmpeg
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error. A remote attacker can trigger denial of service conditions via a crafted mov file.
How to mitigate CVE-2017-9608
Update to version 3.3.3.
Sources
- http://www.openwall.com/lists/oss-security/2017/08/14/1
- http://www.openwall.com/lists/oss-security/2017/08/15/8
- http://www.securityfocus.com/bid/100348
- https://github.com/FFmpeg/FFmpeg/commit/0a709e2a10b8288a0cc383547924ecfe285cef89
- https://github.com/FFmpeg/FFmpeg/commit/31c1c0b46a7021802c3d1d18039fca30dba5a14e
- https://github.com/FFmpeg/FFmpeg/commit/611b35627488a8d0763e75c25ee0875c5b7987dd
- https://www.debian.org/security/2017/dsa-3957