Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from heap and/or stack memory via a crafted MP4 file.
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ffmpeg | Ffmpeg | * | 2.4.6 (excluding) |
Ffmpeg | Ubuntu | zesty | * |
Libav | Ubuntu | esm-infra-legacy/trusty | * |
Libav | Ubuntu | trusty | * |
Libav | Ubuntu | trusty/esm | * |
Mplayer | Ubuntu | artful | * |
Mplayer | Ubuntu | upstream | * |
Mplayer | Ubuntu | zesty | * |
Vlc | Ubuntu | artful | * |
Vlc | Ubuntu | zesty | * |