Input validation error in FFmpeg - CVE-2017-14059

 

Input validation error in FFmpeg - CVE-2017-14059

Published: August 31, 2017 / Updated: August 4, 2020


Vulnerability identifier: #VU33776
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14059
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

In FFmpeg 3.3.3, a DoS in cine_read_header() due to lack of an EOF check might cause huge CPU and memory consumption. When a crafted CINE file, which claims a large "duration" field in the header but does not contain sufficient backing data, is provided, the image-offset parsing loop would consume huge CPU and memory resources, since there is no EOF check inside the loop.


Affected software

FFmpeg
Arch Linux
ffmpeg (Alpine package)

How to mitigate CVE-2017-14059

Install update from vendor's website.

ffmpeg (Alpine package) - update to 3.1.11-r1

External References

Related Security Bulletins