CVE-2015-3417
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-3417
Vendor advisory: cve@mitre.org — https://github.com/FFmpeg/FFmpeg/commit/e8714f6f93d1a32f4e4655209960afcf4c185214
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 7:2.6.1-1 |
| debian | bullseye | fixed | 7:2.6.1-1 |
| debian | forky | fixed | 7:2.6.1-1 |
| debian | sid | fixed | 7:2.6.1-1 |
| debian | trixie | fixed | 7:2.6.1-1 |
| debian | 8.0 | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ffmpeg | ffmpeg | {"endIncluding":"2.3.5"} | |
References
- http://seclists.org/fulldisclosure/2015/Apr/31
- http://www.debian.org/security/2015/dsa-3288
- http://www.securityfocus.com/bid/74385
- http://www.securitytracker.com/id/1032198
- https://git.libav.org/?p=libav.git%3Ba=blob%3Bf=Changelog%3Bhb=refs/tags/v11.4
- https://github.com/FFmpeg/FFmpeg/commit/e8714f6f93d1a32f4e4655209960afcf4c185214
- https://security.gentoo.org/glsa/201705-08
- https://security-tracker.debian.org/tracker/CVE-2015-3417
Verify integrity in audit chain (admin only). AS-IS.