Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.
[
{
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/5d737a3d0ca2bf0f0c6170096d9d1ca230cf9ee0",
"id": "CVE-2017-9992-31eccf5a",
"target": {
"file": "libavformat/tests/fifo_muxer.c"
},
"digest": {
"line_hashes": [
"171761850885783161694918931923155613653",
"287454683090357633262522277026531572655",
"283892481322314227092797983348005820398",
"220739420317396261739711762453104130432"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/f52fbf4f3ed02a7d872d8a102006f29b4421f360",
"id": "CVE-2017-9992-60fa412b",
"target": {
"file": "libavcodec/dfa.c",
"function": "decode_dds1"
},
"digest": {
"function_hash": "173690714667852622426013926318516017828",
"length": 1168.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/f52fbf4f3ed02a7d872d8a102006f29b4421f360",
"id": "CVE-2017-9992-a8b5c31e",
"target": {
"file": "libavcodec/dfa.c"
},
"digest": {
"line_hashes": [
"49292181257551172576771973708726667050",
"51557325619138272839030920394370860057",
"143321983408069829629295156302111297253",
"168494076503263253939609218673331973402"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9992.json"