First published: Fri Apr 14 2017(Updated: )
FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c and the avcodec_align_dimensions2 function in libavcodec/utils.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | <=2.8.9 | |
Debian GNU/Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7865 has a medium severity rating due to its potential to cause a heap-based buffer overflow.
To fix CVE-2017-7865, upgrade FFmpeg to version 2.8.10 or later.
CVE-2017-7865 affects FFmpeg versions prior to 2.8.10 and Debian GNU/Linux 8.0.
CVE-2017-7865 is an out-of-bounds write vulnerability caused by a heap-based buffer overflow.
CVE-2017-7865 is related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c and the avcodec_align_dimensions2 function in libavcodec/utils.c.