CVE Vulnerabilities

CVE-2018-13301

NULL Pointer Dereference

Published: Jul 05, 2018 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

In FFmpeg 4.0.1, due to a missing check of a profile value before setting it, the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c may trigger a NULL pointer dereference while converting a crafted AVI file to MPEG4, leading to a denial of service.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Ffmpeg Ffmpeg 4.0.1 (including) 4.0.1 (including)
Chromium-browser Ubuntu artful *
Chromium-browser Ubuntu bionic *
Chromium-browser Ubuntu cosmic *
Chromium-browser Ubuntu devel *
Chromium-browser Ubuntu disco *
Chromium-browser Ubuntu eoan *
Chromium-browser Ubuntu esm-apps/noble *
Chromium-browser Ubuntu focal *
Chromium-browser Ubuntu groovy *
Chromium-browser Ubuntu hirsute *
Chromium-browser Ubuntu impish *
Chromium-browser Ubuntu jammy *
Chromium-browser Ubuntu kinetic *
Chromium-browser Ubuntu lunar *
Chromium-browser Ubuntu mantic *
Chromium-browser Ubuntu noble *
Chromium-browser Ubuntu oracular *
Chromium-browser Ubuntu trusty *
Chromium-browser Ubuntu upstream *
Chromium-browser Ubuntu xenial *
Ffmpeg Ubuntu artful *
Gst-libav1.0 Ubuntu artful *
Gst-libav1.0 Ubuntu bionic *
Gst-libav1.0 Ubuntu cosmic *
Gst-libav1.0 Ubuntu disco *
Gst-libav1.0 Ubuntu eoan *
Gst-libav1.0 Ubuntu groovy *
Gst-libav1.0 Ubuntu hirsute *
Gst-libav1.0 Ubuntu impish *
Gst-libav1.0 Ubuntu kinetic *
Gst-libav1.0 Ubuntu lunar *
Gst-libav1.0 Ubuntu mantic *
Gst-libav1.0 Ubuntu trusty *
Gst-libav1.0 Ubuntu xenial *
Mplayer Ubuntu artful *
Mythtv Ubuntu artful *
Mythtv Ubuntu bionic *
Mythtv Ubuntu cosmic *
Mythtv Ubuntu disco *
Mythtv Ubuntu eoan *
Mythtv Ubuntu groovy *
Mythtv Ubuntu hirsute *
Mythtv Ubuntu impish *
Mythtv Ubuntu kinetic *
Mythtv Ubuntu lunar *
Mythtv Ubuntu mantic *
Mythtv Ubuntu trusty *
Mythtv Ubuntu xenial *
Oxide-qt Ubuntu artful *
Oxide-qt Ubuntu esm-infra/xenial *
Oxide-qt Ubuntu trusty *
Oxide-qt Ubuntu xenial *
Vice Ubuntu artful *
Vice Ubuntu bionic *
Vice Ubuntu cosmic *
Vice Ubuntu disco *
Vice Ubuntu eoan *
Vice Ubuntu groovy *
Vice Ubuntu hirsute *
Vice Ubuntu impish *
Vice Ubuntu kinetic *
Vice Ubuntu lunar *
Vice Ubuntu mantic *
Vice Ubuntu trusty *
Vice Ubuntu xenial *
Vlc Ubuntu artful *

Potential Mitigations

References