First published: Fri Dec 23 2016(Updated: )
The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted "strh" structure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | <=3.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7555 has been classified as a moderate severity vulnerability due to its potential for memory leaks.
To fix CVE-2016-7555, upgrade FFmpeg to version 3.1.4 or later.
CVE-2016-7555 is caused by a memory leak vulnerability in the avi_read_header function when decoding specifically crafted AVI files.
FFmpeg versions prior to 3.1.4 are vulnerable to CVE-2016-7555.
The potential impact of CVE-2016-7555 includes increased memory usage which could lead to denial of service in affected applications.