Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.
[ { "signature_type": "Function", "digest": { "function_hash": "173690714667852622426013926318516017828", "length": 1168.0 }, "target": { "function": "decode_dds1", "file": "libavcodec/dfa.c" }, "id": "CVE-2017-9992-60fa412b", "deprecated": false, "signature_version": "v1", "source": "https://github.com/ffmpeg/ffmpeg/commit/f52fbf4f3ed02a7d872d8a102006f29b4421f360" }, { "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "49292181257551172576771973708726667050", "51557325619138272839030920394370860057", "143321983408069829629295156302111297253", "168494076503263253939609218673331973402" ] }, "target": { "file": "libavcodec/dfa.c" }, "id": "CVE-2017-9992-a8b5c31e", "deprecated": false, "signature_version": "v1", "source": "https://github.com/ffmpeg/ffmpeg/commit/f52fbf4f3ed02a7d872d8a102006f29b4421f360" } ]