First published: Sun Sep 06 2015(Updated: )
The sws_init_context function in libswscale/utils.c in FFmpeg before 2.7.2 does not initialize certain pixbuf data structures, which allows remote attackers to cause a denial of service (segmentation violation) or possibly have unspecified other impact via crafted video data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | <=2.7.1 | |
Ubuntu | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6824 is classified as a moderate severity vulnerability that can lead to denial of service.
To fix CVE-2015-6824, upgrade FFmpeg to version 2.7.2 or later.
CVE-2015-6824 affects FFmpeg versions prior to 2.7.2.
CVE-2015-6824 can cause a segmentation violation, resulting in denial of service.
CVE-2015-6824 affects Ubuntu Linux 12.04 when using vulnerable versions of FFmpeg.