libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pixfmt is set, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the vp8decodembrownofilter and pred8x8128dc8c functions.
{ "vanir_signatures": [ { "digest": { "length": 807.0, "function_hash": "63037889122877983806885686506885793535" }, "target": { "file": "libavcodec/webp.c", "function": "vp8_lossy_decode_frame" }, "deprecated": false, "source": "https://github.com/ffmpeg/ffmpeg/commit/6b5d3fb26fb4be48e4966e4b1d97c2165538d4ef", "signature_version": "v1", "id": "CVE-2017-9994-073ac825", "signature_type": "Function" }, { "digest": { "length": 4741.0, "function_hash": "12811538007009368521768820160525171352" }, "target": { "file": "libavcodec/vp8.c", "function": "vp78_decode_frame" }, "deprecated": false, "source": "https://github.com/ffmpeg/ffmpeg/commit/6b5d3fb26fb4be48e4966e4b1d97c2165538d4ef", "signature_version": "v1", "id": "CVE-2017-9994-0803633b", "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "59530602348887585127343468186882345762", "212201494289102489329007751342773101572", "17531334238279980247689878590253058405" ] }, "target": { "file": "libavcodec/vp8.c" }, "deprecated": false, "source": "https://github.com/ffmpeg/ffmpeg/commit/6b5d3fb26fb4be48e4966e4b1d97c2165538d4ef", "signature_version": "v1", "id": "CVE-2017-9994-2789a265", "signature_type": "Line" }, { "digest": { "threshold": 0.9, "line_hashes": [ "276775926823435890395552855712813588257", "329621359807923611954894778885133601440", "31770340694690976363564959590920458536", "140287423863305662298629688925795152162", "201153677553983936514563381634874476530", "84348492142917805256586395988190157211" ] }, "target": { "file": "libavcodec/webp.c" }, "deprecated": false, "source": "https://github.com/ffmpeg/ffmpeg/commit/6b5d3fb26fb4be48e4966e4b1d97c2165538d4ef", "signature_version": "v1", "id": "CVE-2017-9994-3d89ee6c", "signature_type": "Line" } ] }