Input validation error in FFmpeg - CVE-2017-14222

 

Input validation error in FFmpeg - CVE-2017-14222

Published: September 9, 2017 / Updated: August 4, 2020


Vulnerability identifier: #VU33779
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14222
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MOV file, which claims a large "item_count" field in the header but does not contain sufficient backing data, is provided, the loop would consume huge CPU and memory resources, since there is no EOF check inside the loop.


Affected software

FFmpeg
Arch Linux
ffmpeg (Alpine package)

How to mitigate CVE-2017-14222

Install update from vendor's website.

ffmpeg (Alpine package) - update to 3.1.11-r1

External References

Related Security Bulletins