CVE-2017-9995

HIGH

FFmpeg 3.3 - Heap-Based Buffer Overflow in libavcodec/scpr.c

Title source: llm
STIX 2.1

Description

libavcodec/scpr.c in FFmpeg 3.3 before 3.3.1 does not properly validate height and width data, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

References (5)

Core 5
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=1519
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99320
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://github.com/FFmpeg/FFmpeg/commit/7ac5067146613997bb38442cb022d7f41321a706
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=1478

Scores

CVSS v3 7.8
EPSS 0.0157
EPSS Percentile 72.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
ffmpeg/ffmpeg 3.3
Published Jun 28, 2017
Tracked Since Feb 18, 2026