CVE Vulnerabilities

CVE-2019-11338

NULL Pointer Dereference

Published: Apr 19, 2019 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Ffmpeg Ffmpeg 3.4 (including) 3.4 (including)
Ffmpeg Ffmpeg 4.1.2 (including) 4.1.2 (including)
Ffmpeg Ubuntu bionic *
Ffmpeg Ubuntu cosmic *
Ffmpeg Ubuntu disco *
Ffmpeg Ubuntu esm-apps/bionic *
Ffmpeg Ubuntu esm-apps/xenial *
Ffmpeg Ubuntu xenial *

Potential Mitigations

References