CVE-2015-3395: Buffer Overflow
The msrledecodepal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via a crafted image, related to a pixel pointer, which triggers an out-of-bounds array access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3395?
The severity of CVE-2015-3395 is considered to be medium due to potential impacts from crafted images leading to unspecified effects.
How do I fix CVE-2015-3395?
To fix CVE-2015-3395, update to the latest version of FFmpeg or Libav that has patched this vulnerability.
Which versions are affected by CVE-2015-3395?
CVE-2015-3395 affects Libav versions prior to 10.7, FFmpeg versions before 2.0.7, and various versions from 2.2.x to 2.6.x.
What type of attack does CVE-2015-3395 enable?
CVE-2015-3395 allows remote attackers to exploit vulnerabilities by supplying specially crafted images.
Is there a public exploit available for CVE-2015-3395?
As of now, there is no known public exploit specifically targeting CVE-2015-3395.