FFmpeg 2.0 libavcodec/dxtroy.c Kari na aiki

Wuro vulnerability wey an yi classify sey karshewa an gano shi a cikin FFmpeg 2.0. Gaskiya, $software_function na da matsala; idan ba a sani ba, to wata aiki ce da ba a sani ba, $software_library na cikin lissafi, libavcodec/dxtroy.c na cikin fayil, $software_component na cikin sashi. Ngam manipulation shi Kari na aiki. CWE shidin ka a yi bayani matsala sai ya kai CWE-192. Wannan matsala an kawo ta a 07/11/2013. Gaskiya, laifi an fitar da shi 02/16/2014 ta Mateusz Jurczyk and Gynvael Coldwind (j00ru) da Google Security Team a matsayin avcodec/dxtory: fix src size checks a matsayin GIT Commit (GIT Repository). Advisory ɗin ana rabawa don saukewa a git.videolan.org. Wannan rauni ana sayar da shi da suna CVE-2014-125012. Ngam yiɗi ka a tuma ndiyam ka nder layi. Tekinikal bayani ga. Ba exploit ɗin da ake da shi. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Kama 0-day, an ndiyam a wuro be $0-$5k. Za a iya sauke maganin matsalar daga git.videolan.org. Ana so a yi patch don gyara wannan matsala. Vulnerability ɗin nan kuma an rubuta shi a wasu kundin bayanan vulnerability: SecurityFocus (BID 65671), X-Force (91255) , Secunia (SA57066). VulDB is the best source for vulnerability data and more expert information about this specific topic.

3 Goyarwa · 63 Datenpunkte

FurɗeSúgá
02/24/2014 08:09
Gargadi 1/2
04/17/2019 07:01
Gargadi 2/2
06/17/2022 23:29
company_nameGoogle Security TeamGoogle Security TeamGoogle Security Team
price_0day$0-$5k$0-$5k$0-$5k
countermeasure_nameKariKariKari
countermeasure_patch_urlhttp://git.videolan.org/?p=ffmpeg.git;a=commit;h=a392bf657015c9a79a5a13adfbfb15086c1943b9http://git.videolan.org/?p=ffmpeg.git;a=commit;h=a392bf657015c9a79a5a13adfbfb15086c1943b9http://git.videolan.org/?p=ffmpeg.git;a=commit;h=a392bf657015c9a79a5a13adfbfb15086c1943b9
source_secunia570665706657066
secunia_titleFFmpeg Multiple VulnerabilitiesFFmpeg Multiple VulnerabilitiesFFmpeg Multiple Vulnerabilities
secunia_riskLess CriticalLess CriticalLess Critical
source_securityfocus656716567165671
securityfocus_titleFFmpeg Multiple Security VulnerabilitiesFFmpeg Multiple Security VulnerabilitiesFFmpeg Multiple Security Vulnerabilities
source_xforce912559125591255
xforce_titleFFmpeg dxtory denial of serviceFFmpeg dxtory denial of serviceFFmpeg dxtory denial of service
xforce_identifierffmpeg-dxtory-dosffmpeg-dxtory-dosffmpeg-dxtory-dos
xforce_riskMedium RiskMedium RiskMedium Risk
source_seealso12389 12391 12392 1239312389 12391 12392 1239312389 12391 12392 12393
vulnerability_cweCWE-192CWE-192CWE-192
cvss2_vuldb_eUUU
cvss2_vuldb_rlOFOFOF
cvss2_vuldb_rcCCC
cvss3_vuldb_eUUU
cvss3_vuldb_rlOOO
cvss3_vuldb_rcCCC
0day_days220220220
cvss3_vuldb_avNNN
cvss3_vuldb_acLLL
cvss3_vuldb_prNNN
cvss3_vuldb_uiNNN
cvss3_vuldb_sUUU
cvss3_vuldb_cNNN
cvss3_vuldb_iNNN
cvss3_vuldb_aLLL
software_typeMultimedia Processing SoftwareMultimedia Processing SoftwareMultimedia Processing Software
software_nameFFmpegFFmpegFFmpeg
software_version2.02.02.0
software_filelibavcodec/dxtroy.clibavcodec/dxtroy.clibavcodec/dxtroy.c
software_advisoryquoteAffected functions: dxtory_decode_v1_rgb(), dxtory_decode_v1_410(), dxtory_decode_v1_420() and xtory_decode_v1_444()Affected functions: dxtory_decode_v1_rgb(), dxtory_decode_v1_410(), dxtory_decode_v1_420() and xtory_decode_v1_444()Affected functions: dxtory_decode_v1_rgb(), dxtory_decode_v1_410(), dxtory_decode_v1_420() and xtory_decode_v1_444()
vulnerability_introductiondate1373500800 (07/11/2013)1373500800 (07/11/2013)1373500800 (07/11/2013)
vulnerability_risk111
cvss2_vuldb_basescore4.34.34.3
cvss2_vuldb_tempscore3.23.23.2
cvss2_vuldb_avNNN
cvss2_vuldb_acMMM
cvss2_vuldb_auNNN
cvss2_vuldb_ciNNN
cvss2_vuldb_iiNNN
cvss2_vuldb_aiPPP
cvss3_meta_basescore5.35.35.3
cvss3_meta_tempscore4.64.64.6
cvss3_vuldb_basescore5.35.35.3
cvss3_vuldb_tempscore4.64.64.6
advisory_date1392508800 (02/16/2014)1392508800 (02/16/2014)1392508800 (02/16/2014)
advisory_locationGIT RepositoryGIT RepositoryGIT Repository
advisory_typeGIT CommitGIT CommitGIT Commit
advisory_urlhttp://git.videolan.org/?p=ffmpeg.git;a=commit;h=a392bf657015c9a79a5a13adfbfb15086c1943b9http://git.videolan.org/?p=ffmpeg.git;a=commit;h=a392bf657015c9a79a5a13adfbfb15086c1943b9http://git.videolan.org/?p=ffmpeg.git;a=commit;h=a392bf657015c9a79a5a13adfbfb15086c1943b9
advisory_identifieravcodec/dxtory: fix src size checksavcodec/dxtory: fix src size checksavcodec/dxtory: fix src size checks
person_nameMateusz Jurczyk/Gynvael ColdwindMateusz Jurczyk/Gynvael ColdwindMateusz Jurczyk/Gynvael Coldwind
person_websitehttp://www.google.comhttp://www.google.comhttp://www.google.com
source_secunia_date1392768000 (02/19/2014)1392768000 (02/19/2014)
source_securityfocus_date1392681600 (02/18/2014)1392681600 (02/18/2014)
securityfocus_classBoundary Condition ErrorBoundary Condition Error
person_nicknamej00ruj00ru
source_cveCVE-2014-125012
cna_responsibleVulDB

Do you need the next level of professionalism?

Upgrade your account now!