libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ffmpeg | Ffmpeg | 3.4 (including) | 3.4 (including) |
Ffmpeg | Ffmpeg | 4.1.2 (including) | 4.1.2 (including) |
Ffmpeg | Ubuntu | bionic | * |
Ffmpeg | Ubuntu | cosmic | * |
Ffmpeg | Ubuntu | disco | * |
Ffmpeg | Ubuntu | xenial | * |