The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .mov file.
2015-12-24T01:59:06.020
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 8.3 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4