CVE-2015-3395 PUBLISHED

The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via a crafted image, related to a pixel pointer, which triggers an out-of-bounds array access.

EPSS 0.79% · 73.8th percentile

Risk Scores

EPSS Score
0.79%
73.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSchromium-browser0, 45.0.2454.101-0ubuntu1.1201
Ubuntu:Pro:14.04:LTSlibav6:9.10-1ubuntu1, 6:9.10-1ubuntu2, 6:9.10-1ubuntu5
Ubuntu:14.04:LTSchromium-browser44.0.2403.89-0ubuntu0.14.04.1.1095, 0, 45.0.2454.101-0ubuntu0.14.04.1.1099

Timeline

References

Open in Interactive Console →