Wind River Support Network

HomeDefectsLIN9-5383
Fixed

LIN9-5383 : Security Advisory - ffmpeg - CVE-2017-14225

Created: Sep 14, 2017    Updated: Dec 3, 2018
Resolved Date: Sep 26, 2017
Found In Version: 9.0.0.10
Fix Version: 9.0.0.11
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Userspace

Description

The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, leading to a NULL pointer dereference. (It is also conceivable that there is security relevance for a NULL pointer dereference in av_color_primaries_name calls within the ffprobe command-line program.)

https://nvd.nist.gov/vuln/detail/CVE-2017-14225

Other Downloads


CVEs


Live chat
Online