#VU14532 Assertion failure in FFmpeg - CVE-2018-15822
Published: August 24, 2018 / Updated: August 27, 2018
FFmpeg
ffmpeg.sourceforge.net
Description
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists due to insufficient checks for an empty audio packet by the flv_write_packet function, as defined in the libavformat/flvenc.c source code file. A local attacker can access the system and execute a specially crafted application that submits malicious input to trigger an assertion failure and cause the service to crash.