FFmpeg 2.0 mpeg4videodec.c decode_vol_header ବଫର୍ ଓଭରଫ୍ଲୋ

Rakkoon nageenyaa kan ସମସ୍ୟାଜନକ jedhamuun beekamu FFmpeg 2.0 keessatti argameera. Kan miidhamte is hojii decode_vol_header faayilii libavcodec/mpeg4videodec.c keessa. Hojii jijjiirraa gara ବଫର୍ ଓଭରଫ୍ଲୋ geessa. CWE fayyadamuun rakkoo ibsuun gara CWE-119 geessa. Rakkoon kun 07/11/2013 keessatti dhihaateera. Dadhabbii kana yeroo 02/20/2014 maxxanfameera kan maxxansiise Mateusz Jurczyk and Gynvael Coldwind waliin Google Security Team akka avcodec/mpeg4videodec: Check for bitstream overread in decode_vol_header() akka GIT Commit (GIT Repository). Odeeffannoon kun buufachuuf git.videolan.org irratti qoodameera. Dogoggorri kun akka CVE-2014-125005tti beekama. Yaaliin weeraraa fageenya irraa jalqabamuu ni danda'a. Faayidaaleen teeknikaa ni jiru. Meeshaa balaa kana fayyadamuuf hin jiru. Amma, gatii ammee exploit might be approx. USD $0-$5k ta'uu danda'a. Hanqinni kun guyyoota 224 caalaa akka zero-day kan ummataaf hin ifneetti fayyadamee ture. Akka 0-daytti, gatii daldalaa dhoksaa tilmaamame $0-$5k ta'ee ture. Sirreeffamni rakkoo git.videolan.org irratti buufachuuf qophaa’eera. Paachii itti fayyadamuun rakkoo kana furuuf ni gorfama. Hanqinni kunis bu'uuraalee odeeffannoo hanqina biroo keessatti galmaa'ee jira: X-Force (91658). Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.

3 ଆଡାପ୍ଟେସନ୍ · 54 ପଏଣ୍ଟ

ଫିଲ୍ଡସୃଷ୍ଟି ହୋଇଛି
03/13/2014 03:24 PM
ଅଦ୍ୟତନ 1/2
04/17/2019 08:27 AM
ଅଦ୍ୟତନ 2/2
06/17/2022 11:20 PM
software_nameFFmpegFFmpegFFmpeg
software_version2.02.02.0
software_filelibavcodec/mpeg4videodec.clibavcodec/mpeg4videodec.clibavcodec/mpeg4videodec.c
software_functiondecode_vol_headerdecode_vol_headerdecode_vol_header
vulnerability_introductiondate1373500800 (07/11/2013)1373500800 (07/11/2013)1373500800 (07/11/2013)
vulnerability_risk111
cvss2_vuldb_basescore4.34.34.3
cvss2_vuldb_tempscore3.23.23.2
cvss2_vuldb_avNNN
cvss2_vuldb_acMMM
cvss2_vuldb_auNNN
cvss2_vuldb_ciNNN
cvss2_vuldb_iiNNN
cvss2_vuldb_aiPPP
cvss3_meta_basescore5.35.35.3
cvss3_meta_tempscore4.64.64.6
cvss3_vuldb_basescore5.35.35.3
cvss3_vuldb_tempscore4.64.64.6
advisory_date1392854400 (02/20/2014)1392854400 (02/20/2014)1392854400 (02/20/2014)
advisory_locationGIT RepositoryGIT RepositoryGIT Repository
advisory_typeGIT CommitGIT CommitGIT Commit
advisory_urlhttp://git.videolan.org/?p=ffmpeg.git;a=commit;h=3edc3b159503d512c919b3d5902f7026e961823ahttp://git.videolan.org/?p=ffmpeg.git;a=commit;h=3edc3b159503d512c919b3d5902f7026e961823ahttp://git.videolan.org/?p=ffmpeg.git;a=commit;h=3edc3b159503d512c919b3d5902f7026e961823a
advisory_identifieravcodec/mpeg4videodec: Check for bitstream overread in decode_vol_header()avcodec/mpeg4videodec: Check for bitstream overread in decode_vol_header()avcodec/mpeg4videodec: Check for bitstream overread in decode_vol_header()
person_nameMateusz Jurczyk/Gynvael ColdwindMateusz Jurczyk/Gynvael ColdwindMateusz Jurczyk/Gynvael Coldwind
person_websitehttp://www.google.comhttp://www.google.comhttp://www.google.com
company_nameGoogle Security TeamGoogle Security TeamGoogle Security Team
price_0day$0-$5k$0-$5k$0-$5k
countermeasure_nameପ୍ୟାଚ୍ପ୍ୟାଚ୍ପ୍ୟାଚ୍
countermeasure_patch_urlhttp://git.videolan.org/?p=ffmpeg.git;a=commit;h=3edc3b159503d512c919b3d5902f7026e961823ahttp://git.videolan.org/?p=ffmpeg.git;a=commit;h=3edc3b159503d512c919b3d5902f7026e961823ahttp://git.videolan.org/?p=ffmpeg.git;a=commit;h=3edc3b159503d512c919b3d5902f7026e961823a
source_xforce916589165891658
source_seealso12589 12588 12587 12586 12584 12583 1258212589 12588 12587 12586 12584 12583 1258212589 12588 12587 12586 12584 12583 12582
cvss2_vuldb_eUUU
cvss2_vuldb_rlOFOFOF
cvss2_vuldb_rcCCC
cvss3_vuldb_eUUU
cvss3_vuldb_rlOOO
cvss3_vuldb_rcCCC
0day_days224224224
cvss3_vuldb_avNNN
cvss3_vuldb_acLLL
cvss3_vuldb_prNNN
cvss3_vuldb_uiNNN
cvss3_vuldb_sUUU
cvss3_vuldb_cNNN
cvss3_vuldb_iNNN
cvss3_vuldb_aLLL
software_typeMultimedia Processing SoftwareMultimedia Processing Software
xforce_titleFFmpeg decode_vol_header() denial of serviceFFmpeg decode_vol_header() denial of service
xforce_identifierffmpeg-decodevolheader-dosffmpeg-decodevolheader-dos
xforce_riskMedium RiskMedium RiskMedium Risk
vulnerability_cweCWE-119 (ବଫର୍ ଓଭରଫ୍ଲୋ)CWE-119 (ବଫର୍ ଓଭରଫ୍ଲୋ)
source_cveCVE-2014-125005
cna_responsibleVulDB

Might our Artificial Intelligence support you?

Check our Alexa App!