CRITICAL
aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables
Published Jun 4, 2019
9.8
CRITICALCVSS 3.0
EPSS 3.06%
Description
aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- http://www.securityfocus.com/bid/109317 vdb-entryx_refsource_BID
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-4320 Advisory
- https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/9b4004c054964a49c7ba44583f4cee22486dd8f2 x_refsource_CONFIRM
- https://git.ffmpeg.org/gitweb/ffmpeg.git/shortlog/n4.1.4 x_refsource_CONFIRM
- https://github.com/FFmpeg/FFmpeg/commit/ed188f6dcdf0935c939ed813cf8745d50742014b x_refsource_MISCPatchThird Party Advisory
- https://github.com/FFmpeg/FFmpeg/compare/a97ea53...ba11e40 x_refsource_MISCThird Party Advisory
- https://seclists.org/bugtraq/2019/Aug/30 mailing-listx_refsource_BUGTRAQ
- https://security.gentoo.org/glsa/202003-65 vendor-advisoryx_refsource_GENTOO
- https://usn.ubuntu.com/4431-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.debian.org/security/2019/dsa-4502 vendor-advisoryx_refsource_DEBIAN
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/109317 | vdb-entryx_refsource_BID | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-4320 | Advisory | |
| https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/9b4004c054964a49c7ba44583f4cee22486dd8f2 | x_refsource_CONFIRM | |
| https://git.ffmpeg.org/gitweb/ffmpeg.git/shortlog/n4.1.4 | x_refsource_CONFIRM | |
| https://github.com/FFmpeg/FFmpeg/commit/ed188f6dcdf0935c939ed813cf8745d50742014b | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/FFmpeg/FFmpeg/compare/a97ea53...ba11e40 | x_refsource_MISCThird Party Advisory | |
| https://seclists.org/bugtraq/2019/Aug/30 | mailing-listx_refsource_BUGTRAQ | |
| https://security.gentoo.org/glsa/202003-65 | vendor-advisoryx_refsource_GENTOO | |
| https://usn.ubuntu.com/4431-1/ | vendor-advisoryx_refsource_UBUNTU | |
| https://www.debian.org/security/2019/dsa-4502 | vendor-advisoryx_refsource_DEBIAN |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 4, 2019
Updated Aug 4, 2024
Reserved Jun 4, 2019
Link CVE-2019-12730
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data