6.8
CVSSv2

CVE-2015-8365

Published: 26/11/2015 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The smka_decode_frame function in libavcodec/smacker.c in FFmpeg prior to 2.6.5, 2.7.x prior to 2.7.3, and 2.8.x up to and including 2.8.2 does not verify that the data size is consistent with the number of channels, which allows remote malicious users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Smacker data.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 12.04

ffmpeg ffmpeg 2.7.1

ffmpeg ffmpeg 2.7.0

ffmpeg ffmpeg 2.8.2

ffmpeg ffmpeg 2.8.1

ffmpeg ffmpeg 2.6.4

ffmpeg ffmpeg 2.7.2

ffmpeg ffmpeg 2.8.0

Vendor Advisories

Debian Bug report logs - #806519 ffmpeg: CVE-2015-8363 CVE-2015-8364 CVE-2015-8365 Package: src:ffmpeg; Maintainer for src:ffmpeg is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 28 Nov 2015 10:30:01 UTC Severity: important Tags: f ...
Libav could be made to crash or run programs as your login if it opened a specially crafted file ...