First published: Thu Sep 05 2019(Updated: )
FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavcodec/h2645_parse.c mishandles rbsp_buffer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | <=4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-15942 is classified as medium due to the potential for exploitation affecting memory integrity.
To fix CVE-2019-15942, upgrade FFmpeg to version 4.3 or later where the issue is resolved.
CVE-2019-15942 can lead to undefined behavior including crashes or other exploits due to uninitialized values.
FFmpeg versions up to and including 4.2 are affected by CVE-2019-15942.
Yes, CVE-2019-15942 is a recognized vulnerability documented in FFmpeg's security advisories.