Vulnerability Name: | CVE-2016-6881 (CCN-120176) | ||||||||||||||||||||||||
Assigned: | 2016-12-23 | ||||||||||||||||||||||||
Published: | 2016-12-23 | ||||||||||||||||||||||||
Updated: | 2016-12-24 | ||||||||||||||||||||||||
Summary: | The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loop denial of service via a crafted SWF file. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-399 | ||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-6881 Source: CCN Type: oss-sec mailing list, Mon, 26 Sep 2016 06:42:38 +0000 [CVE-2016-6881] ffmpeg endless loop when dealing with craft swf file Source: CCN Type: oss-sec mailing list, Sat, 8 Oct 2016 07:09:17 +0000 ffmpeg before 3.1.4 [CVE-2016-7562] [CVE-2016-7122] [CVE-2016-7450] [CVE-2016-7502] [CVE-2016-7555] [CVE-2016-7785] [CVE-2016-7905] Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20160926 [CVE-2016-6881] ffmpeg endless loop when dealing with craft swf file. Source: BID Type: UNKNOWN 93163 Source: XF Type: UNKNOWN ffmpeg-cve20166881-dos(120176) Source: CCN Type: FFmpeg Web site FFmpeg Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-6881 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |