8.8
CVSSv3

CVE-2017-14169

Published: 07/09/2017 Updated: 04/01/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, which claims a large "item_num" field such as 0xffffffff, is provided. As a result, the variable "item_num" turns negative, bypassing the check for a large value.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ffmpeg ffmpeg 3.3.3

debian debian linux 9.0

debian debian linux 8.0

Vendor Advisories

In the mxf_read_primer_pack function in libavformat/mxfdecc in FFmpeg 333, an integer signedness error might occur when a crafted file, which claims a large "item_num" field such as 0xffffffff, is provided As a result, the variable "item_num" turns negative, bypassing the check for a large value ...