Candidate: CVE-2018-6621 PublicDate: 2018-02-05 04:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6621 https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/118e1b0b3370dd1c0da442901b486689efd1654b Description: The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of service (out of array read) via a crafted AVI file. Ubuntu-Description: It was discovered that FFmpeg incorrectly handled certain AVI files. If a user were tricked into opening a crafted multimedia file, an attacker could cause a denial of service via application crash. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_ffmpeg: upstream_ffmpeg: released (7:3.4.2-1) precise/esm_ffmpeg: DNE trusty_ffmpeg: DNE trusty/esm_ffmpeg: DNE xenial_ffmpeg: not-affected (code not present) artful_ffmpeg: ignored (reached end-of-life) bionic_ffmpeg: not-affected (7:3.4.2-2) cosmic_ffmpeg: not-affected (7:3.4.2-2build2) disco_ffmpeg: not-affected (7:3.4.2-2build2) eoan_ffmpeg: not-affected (7:3.4.2-2build2) focal_ffmpeg: not-affected (7:3.4.2-2build2) devel_ffmpeg: not-affected (7:3.4.2-2build2)