Input validation error in FFmpeg - CVE-2017-14055

 

Input validation error in FFmpeg - CVE-2017-14055

Published: August 31, 2017 / Updated: August 4, 2020


Vulnerability identifier: #VU33764
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14055
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MV file, which claims a large "nb_frames" field in the header but does not contain sufficient backing data, is provided, the loop over the frames would consume huge CPU and memory resources, since there is no EOF check inside the loop.


Affected software

FFmpeg
Arch Linux
ffmpeg (Alpine package)

How to mitigate CVE-2017-14055

Install update from vendor's website.

ffmpeg (Alpine package) - update to 3.1.11-r1

External References

Related Security Bulletins