Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.
References
Configurations
History
21 Nov 2024, 02:29
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2015/Apr/31 - Third Party Advisory, VDB Entry | |
References | () http://www.debian.org/security/2015/dsa-3288 - Third Party Advisory | |
References | () http://www.securityfocus.com/bid/74385 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1032198 - Third Party Advisory, VDB Entry | |
References | () https://git.libav.org/?p=libav.git%3Ba=blob%3Bf=Changelog%3Bhb=refs/tags/v11.4 - | |
References | () https://github.com/FFmpeg/FFmpeg/commit/e8714f6f93d1a32f4e4655209960afcf4c185214 - Patch, Vendor Advisory | |
References | () https://security.gentoo.org/glsa/201705-08 - |
07 Nov 2023, 02:25
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2015-04-24 17:59
Updated : 2024-11-21 02:29
NVD link : CVE-2015-3417
Mitre link : CVE-2015-3417
CVE.ORG link : CVE-2015-3417
JSON object : View
Products Affected
debian
- debian_linux
ffmpeg
- ffmpeg
CWE