CVE-2019-9721: Medium severity FFmpeg FFmpeg vulnerability
A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, because handleopenbrace in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this denial of service vulnerability in FFmpeg?
The vulnerability ID is CVE-2019-9721.
What is the severity level of CVE-2019-9721?
The severity level of CVE-2019-9721 is medium, with a severity value of 6.5.
Which software versions are affected by CVE-2019-9721?
FFmpeg versions 3.2 and 4.1 are affected by CVE-2019-9721.
How can an attacker exploit CVE-2019-9721?
An attacker can exploit CVE-2019-9721 by using a crafted video file in Matroska format to hog the CPU through the subtitle decoder in FFmpeg.
Are there any references available for CVE-2019-9721?
Yes, you can find references for CVE-2019-9721 at the following links: - http://www.securityfocus.com/bid/107384 - https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/894995c41e0795c7a44f81adc4838dedc3932e65 - https://github.com/FFmpeg/FFmpeg/commit/273f2755ce8635d42da3cde0eeba15b2e7842774