CVE-2018-12458 PUBLISHED

An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to a denial of service.

EPSS 0.96% · 76.4th percentile

Risk Scores

EPSS Score
0.96%
76.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSffmpeg0, 7:3.3.4-2, 7:3.3.4-2build3
Ubuntu:16.04:LTSffmpeg7:2.8.6-1ubuntu2, 7:2.8.8-0ubuntu0.16.04.1, 0

Timeline

References

Open in Interactive Console →