Vulnerability CVE-2017-14054: Information
Description
In libavformat/rmdec.c in FFmpeg 3.3.3, a DoS in ivr_read_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted IVR file, which claims a large "len" field in the header but does not contain sufficient backing data, is provided, the first type==4 loop would consume huge CPU resources, since there is no EOF check inside the loop.
Severity: MEDIUM (6.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
ffmpeg | sisyphus | 3.3.4-alt1 | 6.1.1-alt3 | ALT-PU-2017-2226-1 | 188343 | Fixed |
ffmpeg | p10 | 3.3.4-alt1 | 4.4.4-alt1 | ALT-PU-2017-2226-1 | 188343 | Fixed |
ffmpeg | p9 | 3.3.4-alt1 | 4.3.6-alt1 | ALT-PU-2017-2226-1 | 188343 | Fixed |
ffmpeg | c10f1 | 3.3.4-alt1 | 4.4.4-alt1 | ALT-PU-2017-2226-1 | 188343 | Fixed |
ffmpeg | c9f2 | 3.3.4-alt1 | 4.3.6-alt1 | ALT-PU-2017-2226-1 | 188343 | Fixed |
ffmpeg | p11 | 3.3.4-alt1 | 6.1.1-alt3 | ALT-PU-2017-2226-1 | 188343 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://github.com/FFmpeg/FFmpeg/commit/124eb202e70678539544f6268efc98131f19fa49 |
|
100627 | |
DSA-3996 |