First published: Tue Jun 04 2019(Updated: )
aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg FFmpeg | <3.2.14 | |
debian/ffmpeg | 7:4.3.7-0+deb11u1 7:4.3.8-0+deb11u1 7:5.1.6-0+deb12u1 7:7.1-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-12730 is critical with a severity value of 9.8.
The affected software for CVE-2019-12730 includes versions of FFmpeg before 3.2.14 and 4.x before 4.1.4.
To fix CVE-2019-12730 on Ubuntu 18.04, update the 'ffmpeg' package to version 7:3.4.8-0ubuntu0.2 or higher.
To fix CVE-2019-12730 on Ubuntu 20.04, update the 'ffmpeg' package to version 7:4.1.4-1 or higher.
Yes, you can refer to the following links for more information on CVE-2019-12730: SecurityFocus - http://www.securityfocus.com/bid/109317, FFmpeg Git Commit - https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/9b4004c054964a49c7ba44583f4cee22486dd8f2, FFmpeg Git Shortlog - https://git.ffmpeg.org/gitweb/ffmpeg.git/shortlog/n4.1.4.