CVE-2017-15672 on Ubuntu 18.04 LTS (bionic) - low.
Description:
The read_header function in libavcodec/ffv1dec.c in FFmpeg 3.3.4 and earlier allows remote attackers to have unspecified impact via a crafted MP4 file, which triggers an out-of-bounds read.