Executive brief
FFmpeg is a widely used software library for processing multimedia files like videos and audio. A vulnerability in how it handles certain media formats could allow a remote attacker to compromise a system that processes a specially crafted file. This could lead to unauthorized access to data, system instability, or complete takeover of the application using the library.
Technical details
An integer overflow vulnerability exists in the mov_build_index function in libavformat/mov.c in FFmpeg. The flaw is triggered by improper handling of sample size values within MOV files. A remote attacker can exploit this by providing a specially crafted media file that, when processed, causes an integer overflow. This can lead to unspecified impacts, typically including heap-based buffer overflows or memory corruption, potentially allowing for arbitrary code execution or a denial-of-service (DoS) condition. The vulnerability is reachable over the network without authentication or user interaction beyond the application opening the malicious file. The issue was addressed in FFmpeg versions 2.8.8, 3.0.3, and 3.1.1.
Affected products
- FFmpeg FFmpeg before 2.8.8, 3.0.x before 3.0.3, 3.1.x before 3.1.1
Timeline
- 2017-01-23: advisory: NVD publication date