CVE-2019-11338

Name
CVE-2019-11338
Description
libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://github.com/FFmpeg/FFmpeg/commit/54655623a82632e7624714d7b2a3e039dc5faa7e
BID http://www.securityfocus.com/bid/108034
UBUNTU https://usn.ubuntu.com/3967-1/
BUGTRAQ https://seclists.org/bugtraq/2019/May/60
DEBIAN https://www.debian.org/security/2019/dsa-4449
MLIST https://lists.debian.org/debian-lts-announce/2019/05/msg00043.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00012.html
UBUNTU https://usn.ubuntu.com/4431-1/
MISC https://github.com/FFmpeg/FFmpeg/commit/9ccc633068c6fe76989f487c8932bd11886ad65b

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:ffmpeg:ffmpeg:4.1.2:*:*:*:*:*:*:* ffmpeg == None == 4.1.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ffmpeg5 edge-community 4.1.3-r0 None fixed
ffmpeg4 edge-community 4.1.3-r0 None fixed
ffmpeg4 3.22-community 4.1.3-r0 None fixed
ffmpeg4 3.21-community 4.1.3-r0 None fixed
ffmpeg4 3.20-community 4.1.3-r0 None fixed
ffmpeg4 3.19-community 4.1.3-r0 None fixed
ffmpeg4 3.18-community 4.1.3-r0 None fixed
ffmpeg4 3.17-community 4.1.3-r0 None fixed
ffmpeg edge-community 4.1.3-r0 None fixed
ffmpeg 3.22-community 4.1.3-r0 None fixed
ffmpeg 3.21-community 4.1.3-r0 None fixed
ffmpeg 3.20-community 4.1.3-r0 None fixed
ffmpeg 3.19-community 4.1.3-r0 None fixed
ffmpeg 3.18-community 4.1.3-r0 None fixed
ffmpeg 3.17-community 4.1.3-r0 None fixed