Input validation error in FFmpeg - CVE-2017-14056

 

Input validation error in FFmpeg - CVE-2017-14056

Published: August 31, 2017 / Updated: August 4, 2020


Vulnerability identifier: #VU33774
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14056
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted RL2 file, which claims a large "frame_count" field in the header but does not contain sufficient backing data, is provided, the loops (for offset and size tables) would consume huge CPU and memory resources, since there is no EOF check inside these loops.


Affected software

FFmpeg
Arch Linux
ffmpeg (Alpine package)

How to mitigate CVE-2017-14056

Install update from vendor's website.

ffmpeg (Alpine package) - update to 3.1.11-r1

External References

Related Security Bulletins