CVE-2015-3417

Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

07 Nov 2023, 02:25

Type Values Removed Values Added
References
  • {'url': 'https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.4', 'name': 'https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.4', 'tags': ['Release Notes', 'Vendor Advisory'], 'refsource': 'CONFIRM'}
  • () https://git.libav.org/?p=libav.git%3Ba=blob%3Bf=Changelog%3Bhb=refs/tags/v11.4 -

Information

Published : 2015-04-24 17:59

Updated : 2024-02-28 12:20


NVD link : CVE-2015-3417

Mitre link : CVE-2015-3417

CVE.ORG link : CVE-2015-3417


JSON object : View

Products Affected

ffmpeg

  • ffmpeg

debian

  • debian_linux