CVE-2014-9604 PUBLISHED

libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value of a slice height, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Ut Video data, related to the (1) restore_median and (2) restore_median_il functions.

EPSS 0.65% · 70.5th percentile

Risk Scores

EPSS Score
0.65%
70.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlibav0, 6:0.8.7-1ubuntu2, 6:9.10-1ubuntu1

Timeline

References

Open in Interactive Console →