7.5
CVSSv2

CVE-2015-6826

Published: 06/09/2015 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg prior to 2.7.2 does not initialize certain structure members, which allows remote malicious users to cause a denial of service (invalid pointer access) or possibly have unspecified other impact via crafted (1) RV30 or (2) RV40 RealVideo data.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 12.04

ffmpeg ffmpeg

Vendor Advisories

Libav could be made to crash or run programs as your login if it opened a specially crafted file ...