Vulnerability Name: | CCN-90493 | ||||||
Published: | 2014-01-10 | ||||||
Updated: | 2014-01-10 | ||||||
Summary: | FFmpeg could allow a remote attacker to obtain sensitive information, caused by an error during sps parsing of an h264 encoded file. An attacker could exploit this vulnerability to cause an out of bounds read memory access using mismatched luma or chroma bit depths. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||
CVSS v2 Severity: | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: FFmpeg Web site FFmpeg Source: CCN Type: FFmpeg GIT Repository h264: reject mismatching luma/chroma bit depths during sps parsing Source: CCN Type: SA56352 FFmpeg Multiple Vulnerabilities Source: CCN Type: BID-64771 FFmpeg Multiple Remote Security Vulnerabilities Source: XF Type: UNKNOWN ffmpeg-h264-information-disclosure(90493) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |