CVE-2019-17542: Buffer Overflow
FFmpeg before 4.2 has a heap-based buffer overflow in vqadecodechunk because of an out-of-array access in vqadecodeinit in libavcodec/vqavideo.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-17542?
CVE-2019-17542 is a vulnerability in FFmpeg before version 4.2 that allows a heap-based buffer overflow.
What is the severity of CVE-2019-17542?
CVE-2019-17542 has a severity rating of 9.8 out of 10, making it critical.
What software is affected by CVE-2019-17542?
FFmpeg versions 2.8.16 to 4.1.5, as well as certain versions of Ubuntu Linux and Debian Linux, are affected by CVE-2019-17542.
How can I fix CVE-2019-17542?
To fix CVE-2019-17542, update FFmpeg to version 4.2 or later.
Where can I find more information about CVE-2019-17542?
You can find more information about CVE-2019-17542 at the following references: [CVE Details](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17542), [OSS-Fuzz](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15919), [Ubuntu Security Notices](https://ubuntu.com/security/notices/USN-4431-1).