libavcodec/scpr.c in FFmpeg 3.3 before 3.3.1 does not properly validate height and width data, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
[
{
"signature_version": "v1",
"source": "https://github.com/ffmpeg/ffmpeg/commit/7ac5067146613997bb38442cb022d7f41321a706",
"deprecated": false,
"id": "CVE-2017-9995-613de293",
"target": {
"file": "libavcodec/scpr.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"288936973232673811462007086445990452141",
"87827691350688371813282091751633821760",
"98512564616808580406905624037803409547",
"337740432965773949247089766135789082879"
]
},
"signature_type": "Line"
},
{
"signature_version": "v1",
"source": "https://github.com/ffmpeg/ffmpeg/commit/7ac5067146613997bb38442cb022d7f41321a706",
"deprecated": false,
"id": "CVE-2017-9995-b7c4bd99",
"target": {
"function": "decompress_i",
"file": "libavcodec/scpr.c"
},
"digest": {
"length": 4314.0,
"function_hash": "54135245231280412219788487345471907204"
},
"signature_type": "Function"
}
]