CVE Vulnerabilities

CVE-2015-8364

Published: Nov 26, 2015 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via crafted image dimensions in Indeo Video Interactive data.

Affected Software

Name Vendor Start Version End Version
Ffmpeg Ffmpeg 2.6.4 (including) 2.6.4 (including)
Ffmpeg Ffmpeg 2.7.0 (including) 2.7.0 (including)
Ffmpeg Ffmpeg 2.7.1 (including) 2.7.1 (including)
Ffmpeg Ffmpeg 2.7.2 (including) 2.7.2 (including)
Ffmpeg Ffmpeg 2.8.0 (including) 2.8.0 (including)
Ffmpeg Ffmpeg 2.8.1 (including) 2.8.1 (including)
Ffmpeg Ffmpeg 2.8.2 (including) 2.8.2 (including)
Libav Ubuntu esm-infra-legacy/trusty *
Libav Ubuntu precise *
Libav Ubuntu trusty *
Libav Ubuntu trusty/esm *
Libav Ubuntu vivid *

References