6.8
CVSSv2

CVE-2015-8364

Published: 26/11/2015 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg prior to 2.6.5, 2.7.x prior to 2.7.3, and 2.8.x up to and including 2.8.2 allows remote malicious users to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via crafted image dimensions in Indeo Video Interactive data.

Vulnerable Product Search on Vulmon Subscribe to Product

ffmpeg ffmpeg 2.7.1

ffmpeg ffmpeg 2.7.0

ffmpeg ffmpeg 2.8.2

ffmpeg ffmpeg 2.8.1

ffmpeg ffmpeg 2.6.4

ffmpeg ffmpeg 2.7.2

ffmpeg ffmpeg 2.8.0

canonical ubuntu linux 12.04

Vendor Advisories

Debian Bug report logs - #806519 ffmpeg: CVE-2015-8363 CVE-2015-8364 CVE-2015-8365 Package: src:ffmpeg; Maintainer for src:ffmpeg is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 28 Nov 2015 10:30:01 UTC Severity: important Tags: f ...
Libav could be made to crash or run programs as your login if it opened a specially crafted file ...