First published: Mon Nov 13 2017(Updated: )
In Libav through 11.11 and 12.x through 12.1, the smacker_decode_tree function in libavcodec/smacker.c does not properly restrict tree recursion, which allows remote attackers to cause a denial of service (bitstream.c:build_table() out-of-bounds read and application crash) via a crafted Smacker stream.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libav Libav | <=11.11 | |
Libav Libav | =12.0 | |
Libav Libav | =12.1 | |
debian/ffmpeg | 7:4.1.9-0+deb10u1 7:4.1.11-0+deb10u1 7:4.3.6-0+deb11u1 7:5.1.3-1 7:6.0-7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.