CVE-2019-1000016

NameCVE-2019-1000016
DescriptionFFMPEG version 4.1 contains a CWE-129: Improper Validation of Array Index vulnerability in libavcodec/cbs_av1.c that can result in Denial of service. This attack appears to be exploitable via specially crafted AV1 file has to be provided as input. This vulnerability appears to have been fixed in after commit b97a4b658814b2de8b9f2a3bce491c002d34de31.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)
Debian Bugs922066

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ffmpeg (PTS)stretch7:3.2.12-1~deb9u1fixed
stretch (security)7:3.2.14-1~deb9u1fixed
buster7:4.1.3-1fixed
buster (security)7:4.1.4-1~deb10u1fixed
bullseye, sid7:4.1.4-1fixed
libav (PTS)jessie6:11.12-1~deb8u1fixed
jessie (security)6:11.12-1~deb8u7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ffmpegsource(unstable)7:4.1.1-1low922066
ffmpegsourcestretch(not affected)
libavsource(unstable)(unfixed)medium
libavsourcejessie(not affected)

Notes

[stretch] - ffmpeg <not-affected> (Vulnerable code not present)
https://github.com/FFmpeg/FFmpeg/commit/b97a4b658814b2de8b9f2a3bce491c002d34de31#diff-cd7e24986650014d67f484f3ffceef3f
[jessie] - libav <not-affected> (Vulnerable code not present)

Search for package or bug name: Reporting problems