Vulnerability Name:

CVE-2019-11339 (CCN-159892)

Assigned:2019-02-14
Published:2019-02-14
Updated:2019-05-06
Summary:The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via crafted MPEG-4 video data.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
3.3 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
1.7 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-125
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2019-11339

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2020:0024

Source: BID
Type: Third Party Advisory, VDB Entry
108037

Source: XF
Type: UNKNOWN
ffmpeg-cve201911339-dos(159892)

Source: CCN
Type: FFmpeg GIT Repository
avcodec/mpeg4videodec: Clear interlaced_dct for studio profile

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/FFmpeg/FFmpeg/commit/1f686d023b95219db933394a7704ad9aa5f01cbb

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/FFmpeg/FFmpeg/commit/d227ed5d598340e719eff7156b1aa0a4469e9a6a

Source: UBUNTU
Type: UNKNOWN
USN-3967-1

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* (Version >= 4.0 and < 4.0.4)
  • OR cpe:/a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* (Version >= 4.1 and < 4.1.2)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201911339
    V
    CVE-2019-11339
    2022-08-07
    oval:org.opensuse.security:def:3303
    P
    mipv6d-2.0.2.umip.0.4-19.63 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3571
    P
    libXxf86dga1-1.1.4-3.58 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94933
    P
    libavcodec58_134-4.4-150400.1.13 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95201
    P
    libavformat58_76-4.4-150400.1.13 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:74735
    P
    Security update for go1.16 (Important)
    2021-10-06
    oval:org.opensuse.security:def:63236
    P
    salt-api-2019.2.0-4.4 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63439
    P
    libsybdb5-1.1.36-3.3.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62740
    P
    file-roller-3.32.5-1.8 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62733
    P
    avahi-autoipd-0.7-3.6.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62765
    P
    libQt5OpenGLExtensions-devel-static-5.12.7-4.12.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62737
    P
    emacs-x11-25.3-3.6.51 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:64548
    P
    Security update for curl (Moderate)
    2021-07-21
    oval:org.opensuse.security:def:93570
    P
    (Critical)
    2021-06-21
    oval:org.opensuse.security:def:100283
    P
    (Moderate)
    2021-05-27
    oval:org.opensuse.security:def:64490
    P
    Security update for avahi (Moderate)
    2021-05-04
    oval:org.opensuse.security:def:64660
    P
    Security update for bind (Important)
    2021-03-02
    oval:org.opensuse.security:def:64281
    P
    Security update for xen (Moderate)
    2020-12-18
    oval:org.opensuse.security:def:64280
    P
    Security update for openssh (Moderate)
    2020-12-17
    oval:org.opensuse.security:def:63586
    P
    libntfs-3g87-2016.2.22-3.3.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62943
    P
    crash-7.2.8-16.19 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25063
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25769
    P
    Security update for gd (Low)
    2020-12-01
    oval:org.opensuse.security:def:64144
    P
    Security update for java-1_7_1-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25255
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25827
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25393
    P
    Security update for libqt5-qtbase (Important)
    2020-12-01
    oval:org.opensuse.security:def:26500
    P
    Security update for ffmpeg-4 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25628
    P
    Security update for dpdk (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25052
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74602
    P
    Security update for rubygem-actionpack-5_1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:64388
    P
    libssh-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63815
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25127
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25051
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25783
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25336
    P
    Security update for gcc10 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26465
    P
    Security update for enigmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25477
    P
    Security update for spectre-meltdown-checker (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25681
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:110397
    P
    Security update for ffmpeg-4 (Moderate)
    2020-01-13
    oval:com.ubuntu.disco:def:2019113390000000
    V
    CVE-2019-11339 on Ubuntu 19.04 (disco) - medium.
    2019-04-19
    oval:com.ubuntu.cosmic:def:201911339000
    V
    CVE-2019-11339 on Ubuntu 18.10 (cosmic) - medium.
    2019-04-18
    oval:com.ubuntu.bionic:def:2019113390000000
    V
    CVE-2019-11339 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-04-18
    oval:com.ubuntu.bionic:def:201911339000
    V
    CVE-2019-11339 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-04-18
    oval:com.ubuntu.xenial:def:2019113390000000
    V
    CVE-2019-11339 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-04-18
    oval:com.ubuntu.xenial:def:201911339000
    V
    CVE-2019-11339 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-04-18
    oval:com.ubuntu.cosmic:def:2019113390000000
    V
    CVE-2019-11339 on Ubuntu 18.10 (cosmic) - medium.
    2019-04-18
    BACK
    ffmpeg ffmpeg *
    ffmpeg ffmpeg *