8.8
CVSSv3

CVE-2016-2330

Published: 12/02/2016 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

libavcodec/gif.c in FFmpeg prior to 2.8.6 does not properly calculate a buffer size, which allows remote malicious users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .tga file, related to the gif_image_write_image, gif_encode_init, and gif_encode_close functions.

Vulnerable Product Search on Vulmon Subscribe to Product

ffmpeg ffmpeg

canonical ubuntu linux 12.04

Vendor Advisories

Libav could be made to crash or run programs as your login if it opened a specially crafted file ...