CVE-2019-17542 PUBLISHED

FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because of an out-of-array access in vqa_decode_init in libavcodec/vqavideo.c.

EPSS 0.82% · 74.2th percentile

Risk Scores

EPSS Score
0.82%
74.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSffmpeg0, 7:3.3.4-2, 7:3.3.4-2build3
Ubuntu:16.04:LTSffmpeg7:2.8.10-0ubuntu0.16.04.1, 7:2.8.11-0ubuntu0.16.04.1, 0

Timeline

References

Open in Interactive Console →