Aurelien Jacobs

2 exploits Active since Sep 2019
CVE-2019-9717 WRITEUP MEDIUM WRITEUP
Libav <12.3 - DoS
In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c has a complex format argument to sscanf.
CVSS 6.5
CVE-2019-9720 WRITEUP MEDIUM WRITEUP
Libav 12.3 - Buffer Overflow
A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misuses snprintf.
CVSS 6.5