Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check chunk size.
2017-02-09T15:59:00.753
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ffmpeg | ffmpeg | ≤ 2.8.9 | Yes |
Application | ffmpeg | ffmpeg | 3.0 | Yes |
Application | ffmpeg | ffmpeg | 3.0.1 | Yes |
Application | ffmpeg | ffmpeg | 3.0.2 | Yes |
Application | ffmpeg | ffmpeg | 3.0.3 | Yes |
Application | ffmpeg | ffmpeg | 3.0.4 | Yes |
Application | ffmpeg | ffmpeg | 3.1 | Yes |
Application | ffmpeg | ffmpeg | 3.1.1 | Yes |
Application | ffmpeg | ffmpeg | 3.1.2 | Yes |
Application | ffmpeg | ffmpeg | 3.1.3 | Yes |
Application | ffmpeg | ffmpeg | 3.1.4 | Yes |
Application | ffmpeg | ffmpeg | 3.1.5 | Yes |
Application | ffmpeg | ffmpeg | 3.2 | Yes |
Application | ffmpeg | ffmpeg | 3.2.1 | Yes |