CVE Vulnerabilities

CVE-2018-13303

NULL Pointer Dereference

Published: Jul 05, 2018 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

In FFmpeg 4.0.1, a missing check for failure of a call to init_get_bits8() in the avpriv_ac3_parse_header function in libavcodec/ac3_parser.c may trigger a NULL pointer dereference while converting a crafted AVI file to MPEG4, leading to a denial of service.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
FfmpegFfmpeg4.0.1 (including)4.0.1 (including)
Chromium-browserUbuntuartful*
Chromium-browserUbuntubionic*
Chromium-browserUbuntucosmic*
Chromium-browserUbuntudevel*
Chromium-browserUbuntudisco*
Chromium-browserUbuntueoan*
Chromium-browserUbuntuesm-apps/noble*
Chromium-browserUbuntufocal*
Chromium-browserUbuntugroovy*
Chromium-browserUbuntuhirsute*
Chromium-browserUbuntuimpish*
Chromium-browserUbuntujammy*
Chromium-browserUbuntukinetic*
Chromium-browserUbuntulunar*
Chromium-browserUbuntumantic*
Chromium-browserUbuntunoble*
Chromium-browserUbuntuoracular*
Chromium-browserUbuntuplucky*
Chromium-browserUbuntuquesting*
Chromium-browserUbuntutrusty*
Chromium-browserUbuntuupstream*
Chromium-browserUbuntuxenial*
FfmpegUbuntuartful*
Gst-libav1.0Ubuntuartful*
Gst-libav1.0Ubuntubionic*
Gst-libav1.0Ubuntucosmic*
Gst-libav1.0Ubuntudisco*
Gst-libav1.0Ubuntueoan*
Gst-libav1.0Ubuntufocal*
Gst-libav1.0Ubuntugroovy*
Gst-libav1.0Ubuntuhirsute*
Gst-libav1.0Ubuntuimpish*
Gst-libav1.0Ubuntukinetic*
Gst-libav1.0Ubuntulunar*
Gst-libav1.0Ubuntumantic*
Gst-libav1.0Ubuntuoracular*
Gst-libav1.0Ubuntuplucky*
Gst-libav1.0Ubuntutrusty*
Gst-libav1.0Ubuntuxenial*
KinoUbuntuartful*
KinoUbuntubionic*
KinoUbuntucosmic*
KinoUbuntudisco*
KinoUbuntueoan*
KinoUbuntufocal*
KinoUbuntugroovy*
KinoUbuntuhirsute*
KinoUbuntuimpish*
KinoUbuntutrusty*
KinoUbuntuxenial*
MplayerUbuntuartful*
MythtvUbuntuartful*
MythtvUbuntubionic*
MythtvUbuntucosmic*
MythtvUbuntudisco*
MythtvUbuntueoan*
MythtvUbuntufocal*
MythtvUbuntugroovy*
MythtvUbuntuhirsute*
MythtvUbuntuimpish*
MythtvUbuntukinetic*
MythtvUbuntulunar*
MythtvUbuntumantic*
MythtvUbuntuoracular*
MythtvUbuntuplucky*
MythtvUbuntutrusty*
MythtvUbuntuxenial*
Oxide-qtUbuntuartful*
Oxide-qtUbuntuesm-infra/xenial*
Oxide-qtUbuntutrusty*
Oxide-qtUbuntuxenial*
VlcUbuntuartful*

Potential Mitigations

References