~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2017-14222

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2017-14222
2
 
PublicDate: 2017-09-08
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14222
5
 
 https://github.com/FFmpeg/FFmpeg/commit/9cb4eb772839c5e1de2855d126bf74ff16d13382
6
 
Description:
7
 
 In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of
8
 
 an EOF (End of File) check might cause huge CPU and memory consumption.
9
 
 When a crafted MOV file, which claims a large "item_count" field in the
10
 
 header but does not contain sufficient backing data, is provided, the loop
11
 
 would consume huge CPU and memory resources, since there is no EOF check
12
 
 inside the loop.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
Bugs:
16
 
Priority: low
17
 
Discovered-by:
18
 
Assigned-to:
19
 
 
20
 
Patches_libav:
21
 
upstream_libav: needs-triage
22
 
precise/esm_libav: DNE
23
 
trusty_libav: needs-triage
24
 
vivid/ubuntu-core_libav: DNE
25
 
xenial_libav: DNE
26
 
zesty_libav: DNE
27
 
artful_libav: DNE
28
 
bionic_libav: DNE
29
 
devel_libav: DNE
30
 
 
31
 
Patches_ffmpeg:
32
 
upstream_ffmpeg: needs-triage
33
 
precise/esm_ffmpeg: DNE
34
 
trusty_ffmpeg: DNE
35
 
vivid/ubuntu-core_ffmpeg: DNE
36
 
xenial_ffmpeg: released (7:2.8.14-0ubuntu0.16.04.1)
37
 
zesty_ffmpeg: ignored (reached end-of-life)
38
 
artful_ffmpeg: needs-triage
39
 
bionic_ffmpeg: needs-triage
40
 
devel_ffmpeg: needs-triage