Out-of-bounds Read Affecting ffmpeg package, versions [,3.4.3)


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.54% (78th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-FFMPEG-2369087
  • published26 Jan 2022
  • disclosed23 Jul 2018
  • creditUnknown

Introduced: 23 Jul 2018

CVE-2018-1999010  (opens in a new tab)
CWE-125  (opens in a new tab)

How to fix?

Upgrade ffmpeg to version 3.4.3 or higher.

Overview

Affected versions of this package are vulnerable to Out-of-bounds Read. FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can result in attackers accessing out of bound data. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in cced03dd667a5df6df8fd40d8de0bff477ee02e8 and later.

References

CVSS Scores

version 3.1