Input validation error in Debian Linux - CVE-2015-3417

 

Input validation error in Debian Linux - CVE-2015-3417

Published: April 24, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40808
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3417
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows remote attackers to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.


Affected software

Debian Linux
Gentoo Linux
media-video/libav

How to mitigate CVE-2015-3417

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

media-video/libav - update to 11.8

External References

Related Security Bulletins