FFmpeg.m3u8.File.EXTINF.Duration.Use.After.Free
Description
This indicates an attack attempt against an Integer Overflow vulnerability in FFmpeg.
The vulnerability is caused by an error when the vulnerable software handles a specially crafted media file. A remote unauthenticated attacker may be able to exploit this to execute arbitrary code, via a crafted media file.
Affected Products
FFmpeg 4.3
FFmpeg 4.2.x prior to 4.2.4
FFmpeg 4.1.x prior to 4.1.6
FFmpeg 4.0.x prior to 4.0.6
FFmpeg 3.4.x prior to 3.4.8
FFmpeg 3.3.4 and up
FFmpeg 3.2.10 prior to 3.2.15
FFmpeg 1.2
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the latest update from the vendor.
https://www.ffmpeg.org/security.html
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |