CVE-2019-11338: Null Pointer Dereference
Last updated 25 August 2025
Other sources
libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-11338?
CVE-2019-11338 is a vulnerability in FFmpeg 3.4 and 4.1.2 that mishandles detection of duplicate first slices in HEVC data.
What is the severity of CVE-2019-11338?
The severity of CVE-2019-11338 is high, with a CVSS score of 8.8.
How does CVE-2019-11338 impact the system?
CVE-2019-11338 can cause a denial of service (NULL pointer dereference and out-of-array access) or potentially have unspecified other impact via crafted HEVC data.
Which versions of FFmpeg are affected by CVE-2019-11338?
FFmpeg versions 3.4 and 4.1.2 are affected by CVE-2019-11338.
Where can I find more information about CVE-2019-11338?
You can find more information about CVE-2019-11338 on the following references: [1] [2] [3].