FFmpeg 2.0 libavcodec/h264.c output_frame ବଫର୍ ଓଭରଫ୍ଲୋ

Dogoggorri kan akka ସମସ୍ୟାଜନକ jedhamuun ramadame FFmpeg 2.0 keessatti argameera. Miidhamni argame is hojii output_frame faayilii libavcodec/h264.c keessa. Wanti jijjiirame gara ବଫର୍ ଓଭରଫ୍ଲୋ geessa. Rakkoo ibsuuf CWE yoo fayyadamte gara CWE-119 si geessa. Madda rakkoo kanaa 07/11/2013 irratti argameera. Odeeffannoon kun yeroo 02/21/2014 maxxanfameera kan maxxansiise Mateusz Jurczyk and Gynvael Coldwind waliin Google Security Team akka avcodec/h264: use subsample factors of the used pixel format akka GIT Commit (GIT Repository). Odeeffannoon kun buufachuuf git.videolan.org irratti argama. Dogoggorri kun CVE-2014-125006 jedhamee waamama. Weerara fageenya irraa jalqabuu ni danda'ama. Ibsa teeknikaa ni jira. Meeshaa balaa kana fayyadamuuf hin jirre. Ammas, gatii exploit might be approx. USD $0-$5k yeroo ammaa irratti argamuu danda'a. Hanqinni kun guyyoota 225 ol tajaajila zero-day kan hin beekkaminitti fayyadamee ture. Akka 0-daytti, gatiin isaa daldala dhoksaa keessatti $0-$5k akka ta'e tilmaamameera. Sirreeffamni dogoggoraa git.videolan.org irraa buufachuuf qophaa’eera. Yaada kennamu, rakkoo kana furuuf paachii itti fayyadamuun ni gorfama. Hanqinni kun bu'uuraalee odeeffannoo hanqina biroo keessatti argama: X-Force (91657) , Secunia (SA57282). If you want to get best quality of vulnerability data, you may have to visit VulDB.

3 ଆଡାପ୍ଟେସନ୍ · 58 ପଏଣ୍ଟ

ଫିଲ୍ଡସୃଷ୍ଟି ହୋଇଛି
03/13/2014 03:24 PM
ଅଦ୍ୟତନ 1/2
04/17/2019 08:15 AM
ଅଦ୍ୟତନ 2/2
06/17/2022 11:21 PM
software_nameFFmpegFFmpegFFmpeg
software_version2.02.02.0
software_filelibavcodec/h264.clibavcodec/h264.clibavcodec/h264.c
software_functionoutput_frameoutput_frameoutput_frame
vulnerability_introductiondate1373500800 (07/11/2013)1373500800 (07/11/2013)1373500800 (07/11/2013)
vulnerability_risk111
cvss2_vuldb_basescore4.34.34.3
cvss2_vuldb_tempscore3.23.23.2
cvss2_vuldb_avNNN
cvss2_vuldb_acMMM
cvss2_vuldb_auNNN
cvss2_vuldb_ciNNN
cvss2_vuldb_iiNNN
cvss2_vuldb_aiPPP
cvss3_meta_basescore5.35.35.3
cvss3_meta_tempscore4.64.64.6
cvss3_vuldb_basescore5.35.35.3
cvss3_vuldb_tempscore4.64.64.6
advisory_date1392940800 (02/21/2014)1392940800 (02/21/2014)1392940800 (02/21/2014)
advisory_locationGIT RepositoryGIT RepositoryGIT Repository
advisory_typeGIT CommitGIT CommitGIT Commit
advisory_urlhttp://git.videolan.org/?p=ffmpeg.git;a=commit;h=8c55ff393340998faae887dfac19e7ef128e1e58http://git.videolan.org/?p=ffmpeg.git;a=commit;h=8c55ff393340998faae887dfac19e7ef128e1e58http://git.videolan.org/?p=ffmpeg.git;a=commit;h=8c55ff393340998faae887dfac19e7ef128e1e58
advisory_identifieravcodec/h264: use subsample factors of the used pixel formatavcodec/h264: use subsample factors of the used pixel formatavcodec/h264: use subsample factors of the used pixel format
person_nameMateusz Jurczyk/Gynvael ColdwindMateusz Jurczyk/Gynvael ColdwindMateusz Jurczyk/Gynvael Coldwind
person_websitehttp://www.google.comhttp://www.google.comhttp://www.google.com
company_nameGoogle Security TeamGoogle Security TeamGoogle Security Team
price_0day$0-$5k$0-$5k$0-$5k
countermeasure_nameପ୍ୟାଚ୍ପ୍ୟାଚ୍ପ୍ୟାଚ୍
countermeasure_patch_urlhttp://git.videolan.org/?p=ffmpeg.git;a=commit;h=8c55ff393340998faae887dfac19e7ef128e1e58http://git.videolan.org/?p=ffmpeg.git;a=commit;h=8c55ff393340998faae887dfac19e7ef128e1e58http://git.videolan.org/?p=ffmpeg.git;a=commit;h=8c55ff393340998faae887dfac19e7ef128e1e58
source_xforce916579165791657
source_seealso12582 12583 12586 1258812582 12583 12586 1258812582 12583 12586 12588
cvss2_vuldb_eUUU
cvss2_vuldb_rlOFOFOF
cvss2_vuldb_rcCCC
cvss3_vuldb_eUUU
cvss3_vuldb_rlOOO
cvss3_vuldb_rcCCC
0day_days225225225
cvss3_vuldb_avNNN
cvss3_vuldb_acLLL
cvss3_vuldb_prNNN
cvss3_vuldb_uiNNN
cvss3_vuldb_sUUU
cvss3_vuldb_cNNN
cvss3_vuldb_iNNN
cvss3_vuldb_aLLL
software_typeMultimedia Processing SoftwareMultimedia Processing Software
source_secunia5728257282
source_secunia_date1394150400 (03/07/2014)1394150400 (03/07/2014)
secunia_titleFFmpeg Multiple VulnerabilitiesFFmpeg Multiple Vulnerabilities
secunia_riskLess CriticalLess CriticalLess Critical
xforce_titleFFmpeg output_frame() denial of serviceFFmpeg output_frame() denial of service
xforce_identifierffmpeg-outputframe-dosffmpeg-outputframe-dos
xforce_riskMedium RiskMedium RiskMedium Risk
vulnerability_cweCWE-119 (ବଫର୍ ଓଭରଫ୍ଲୋ)CWE-119 (ବଫର୍ ଓଭରଫ୍ଲୋ)
source_cveCVE-2014-125006
cna_responsibleVulDB

Might our Artificial Intelligence support you?

Check our Alexa App!