Use-after-free in FFmpeg - CVE-2018-1999013

 

Use-after-free in FFmpeg - CVE-2018-1999013

Published: July 23, 2018 / Updated: July 28, 2020


Vulnerability identifier: #VU32008
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1999013
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when processing specially crafted RM file has to be provided as input. This vulnerability appears to have been fixed in a7e032a277452366771951e29fd0bf2bd5c029f0 and later. A attacker to read heap memory. This attack appear can be exploitable.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

FFmpeg
ffmpeg (Alpine package)

How to mitigate CVE-2018-1999013

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

ffmpeg (Alpine package) - update to 4.1.4-r0

External References

Related Security Bulletins