aa_read_header in libavformat/aadec.c in FFmpeg prior to 3.2.14 and 4.x prior to 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ffmpeg ffmpeg |