libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pixfmt is set, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the vp8decodembrownofilter and pred8x8128dc8c functions.
[
{
"id": "CVE-2017-9994-31eccf5a",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"171761850885783161694918931923155613653",
"287454683090357633262522277026531572655",
"283892481322314227092797983348005820398",
"220739420317396261739711762453104130432"
]
},
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/5d737a3d0ca2bf0f0c6170096d9d1ca230cf9ee0",
"signature_type": "Line",
"target": {
"file": "libavformat/tests/fifo_muxer.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9994.json"