Vulnerabilities > CVE-2016-7122 - Resource Management Errors vulnerability in Ffmpeg

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
ffmpeg
CWE-399
nessus

Summary

The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted 'nctg' structure.

Vulnerable Configurations

Part Description Count
Application
Ffmpeg
295

Common Weakness Enumeration (CWE)

Nessus

NASL familyGentoo Local Security Checks
NASL idGENTOO_GLSA-201701-71.NASL
descriptionThe remote host is affected by the vulnerability described in GLSA-201701-71 (FFmpeg: Multiple vulnerabilities) Multiple vulnerabilities have been discovered in FFmpeg. Please review the CVE identifiers referenced below for details. Impact : Remote attackers could cause a Denial of Service condition via various crafted media file types or have other unspecified impacts. Workaround : There is no known workaround at this time.
last seen2020-06-01
modified2020-06-02
plugin id96857
published2017-01-30
reporterThis script is Copyright (C) 2017 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/96857
titleGLSA-201701-71 : FFmpeg: Multiple vulnerabilities