First published: Fri Jun 15 2018(Updated: )
An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to a denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/ffmpeg | 7:4.1.9-0+deb10u1 7:4.1.11-0+deb10u1 7:4.3.6-0+deb11u1 7:5.1.3-1 7:6.0-7 | |
FFmpeg | =2.8 | |
FFmpeg | =4.0 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12458 has been classified as a denial of service vulnerability.
To remediate CVE-2018-12458, update FFmpeg to versions 4.1.9, 4.1.11, 4.3.6, 5.1.3, 6.0 or later.
FFmpeg versions 2.8 and 4.0 are affected by CVE-2018-12458.
CVE-2018-12458 may cause an assertion violation, leading to a denial of service when converting crafted AVI files.
Yes, CVE-2018-12458 affects Debian GNU/Linux 9.0 and potentially other Debian versions with affected FFmpeg packages.