Vulnerability Name: | CVE-2016-7122 (CCN-120175) | ||||||||||||||||||||||||
Assigned: | 2016-12-23 | ||||||||||||||||||||||||
Published: | 2016-12-23 | ||||||||||||||||||||||||
Updated: | 2017-07-01 | ||||||||||||||||||||||||
Summary: | The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted 'nctg' structure. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-399 | ||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-7122 Source: CCN Type: oss-sec mailing list, Sat, 8 Oct 2016 07:09:17 +0000 ffmpeg before 3.1.4 [CVE-2016-7562] [CVE-2016-7122] [CVE-2016-7450] [CVE-2016-7502] [CVE-2016-7555] [CVE-2016-7785] [CVE-2016-7905] Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20161008 ffmpeg before 3.1.4 [CVE-2016-7562] [CVE-2016-7122] [CVE-2016-7450] [CVE-2016-7502] [CVE-2016-7555] [CVE-2016-7785] [CVE-2016-7905] Source: BID Type: UNKNOWN 94839 Source: CCN Type: BID-94839 FFmpeg 'libavformat/avidec.c' Denial of Service Vulnerability Source: XF Type: UNKNOWN ffmpeg-cve20167122-dos(120175) Source: CCN Type: FFmpeg Web site FFmpeg Source: GENTOO Type: UNKNOWN GLSA-201701-71 Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-7122 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |