In FFmpeg 2.4 and 3.3.3, the read_data function in libavformat/hls.c does not restrict reload attempts for an insufficient list, which allows remote attackers to cause a denial of service (infinite loop).
References
Configurations
History
21 Nov 2024, 03:12
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.debian.org/security/2017/dsa-3996 - | |
References | () http://www.securityfocus.com/bid/100629 - | |
References | () https://github.com/FFmpeg/FFmpeg/commit/7ba100d3e6e8b1e5d5342feb960a7f081d6e15af - | |
References | () https://github.com/FFmpeg/FFmpeg/commit/7ec414892ddcad88313848494b6fc5f437c9ca4a - Patch, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2019/03/msg00041.html - |
Information
Published : 2017-08-31 15:29
Updated : 2024-11-21 03:12
NVD link : CVE-2017-14058
Mitre link : CVE-2017-14058
CVE.ORG link : CVE-2017-14058
JSON object : View
Products Affected
ffmpeg
- ffmpeg
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')