FFmpeg before 2017-01-23 has an out-of-bounds write caused by a stack-based buffer overflow related to the decode_zbuf function in libavcodec/pngdec.c.
[
{
"deprecated": false,
"id": "CVE-2017-7866-ec38d51b",
"source": "https://github.com/ffmpeg/ffmpeg/commit/e371f031b942d73e02c090170975561fabd5c264",
"digest": {
"function_hash": "87848245540106794533880653684604751285",
"length": 923.0
},
"target": {
"function": "decode_zbuf",
"file": "libavcodec/pngdec.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2017-7866-f643add8",
"source": "https://github.com/ffmpeg/ffmpeg/commit/e371f031b942d73e02c090170975561fabd5c264",
"digest": {
"line_hashes": [
"26969624828945994574510710227430743973",
"152110117048612621381608563860232678929",
"78619713611657215130901403769945274675",
"226450398239878141006525736976696391881",
"269873381620780376864095488219784657838",
"104794154060694300416873093341203918977",
"86336547730151847623710273798792938735",
"11352064019527706633746525888505553801",
"195565508762400866235641672554865859381",
"63131409930916887312085608251988781036"
],
"threshold": 0.9
},
"target": {
"file": "libavcodec/pngdec.c"
},
"signature_type": "Line",
"signature_version": "v1"
}
]