First published: Sun Sep 06 2015(Updated: )
The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not initialize certain structure members, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other impact via crafted (1) RV30 or (2) RV40 RealVideo data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | =12.04 | |
FFmpeg | <=2.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6826 has a severity rating that indicates it can lead to a denial of service due to invalid pointer access.
To fix CVE-2015-6826, upgrade FFmpeg to version 2.7.2 or later.
FFmpeg versions prior to 2.7.2, specifically up to version 2.7.1, are affected by CVE-2015-6826.
CVE-2015-6826 affects Ubuntu Linux 12.04 and earlier versions of FFmpeg.
CVE-2015-6826 can facilitate remote denial of service attacks through crafted RV30 or RV40 RealVideo streams.