#VU17420 Improper validation of an array index in FFmpeg - CVE-2019-1000016
Published: February 7, 2019
FFmpeg
ffmpeg.sourceforge.net
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation of an array index by the libavcodec/cbs_av1.c source code file. A remote attacker can trick the victim into accessing an AOMedia Video 1 (AV1) file that submits malicious input and cause the service to crash.