DescriptionThe cdg_decode_frame function in cdgraphics.c in libavcodec in FFmpeg before 1.2.1 does not validate the presence of non-header data in a buffer, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via crafted CD Graphics Video data.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ffmpeg (PTS)stretch7:3.2.10-1~deb9u1fixed
stretch (security)7:3.2.12-1~deb9u1fixed
buster, sid7:4.0.2-1fixed
libav (PTS)jessie (security), jessie6:11.12-1~deb8u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ffmpegsource(unstable)(not affected)


- ffmpeg <not-affected> (CD Graphics Video Decoder not present in 0.5 ffmpeg)
Fix in ffmpeg:;a=commit;h=7ef2dbd2392e3e4d430e0173e1e5c4df9f18b6dd
Fix in libav:;a=commit;h=a1599f3f7ea8478d1f6a95e59e3bc6bc86d5f812

Search for package or bug name: Reporting problems