CVE-2018-1999013 PUBLISHED

FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to be exploitable via specially crafted RM file has to be provided as input. This vulnerability appears to have been fixed in a7e032a277452366771951e29fd0bf2bd5c029f0 and later.

EPSS 0.35% · 56.9th percentile

Risk Scores

EPSS Score
0.35%
56.9th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSqtwebengine-opensource-src5.12.8+dfsg-0ubuntu1.1, 5.12.5+dfsg-6ubuntu2, 5.12.8+dfsg-0ubuntu1
Ubuntu:18.04:LTSgst-libav1.01.13.91-1, 1.14.0-1, 1.14.1-1~ubuntu18.04.1
Ubuntu:16.04:LTSgst-libav1.01.8.0-1, 1.8.1-1~ubuntu1, 1.8.2-1~ubuntu1
Ubuntu:22.04:LTSqtwebengine-opensource-src0, 5.15.6+dfsg-2, 5.15.7+dfsg-2
Ubuntu:24.04:LTSqtwebengine-opensource-src5.15.16+dfsg-1ubuntu4, 5.15.16+dfsg-3, 5.15.16+dfsg-1ubuntu2
Ubuntu:24.04:LTSchromium-browser0, 2:1snap1-0ubuntu2, 2:1snap1-0ubuntu1
Ubuntu:18.04:LTSqtwebengine-opensource-src5.9.2+dfsg-2ubuntu1, 0, 5.9.3+dfsg-0ubuntu1
Ubuntu:20.04:LTSgst-libav1.01.16.1-1, 1.16.2-1, 1.16.2-2
Ubuntu:22.04:LTSchromium-browser0, 1:85.0.4183.83-0ubuntu2.22.04.1, 1:85.0.4183.83-0ubuntu2
Ubuntu:22.04:LTSgst-libav1.01.20.0-1, 1.20.1-1, 1.20.3-0ubuntu1
Ubuntu:16.04:LTSoxide-qt1.15.8-0ubuntu0.16.04.1, 1.9.5-0ubuntu1, 1.10.3-0ubuntu0.15.10.1
Ubuntu:24.04:LTSgst-libav1.01.24.1-1build1, 1.24.1-1, 1.22.10-1
Ubuntu:25.10gst-libav1.01.26.0-1, 0, 1.26.1-1
Ubuntu:25.10qtwebengine-opensource-src5.15.19+dfsg2-1, 5.15.19+dfsg-1, 5.15.18+dfsg-2
Ubuntu:25.10chromium-browser0, 2:1snap1-0ubuntu3

Timeline

References

Open in Interactive Console →