libavcodec/scpr.c in FFmpeg 3.3 before 3.3.1 does not properly validate height and width data, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9995.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"288936973232673811462007086445990452141",
"87827691350688371813282091751633821760",
"98512564616808580406905624037803409547",
"337740432965773949247089766135789082879"
],
"threshold": 0.9
},
"id": "CVE-2017-9995-613de293",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/ffmpeg/ffmpeg/commit/7ac5067146613997bb38442cb022d7f41321a706",
"target": {
"file": "libavcodec/scpr.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "54135245231280412219788487345471907204",
"length": 4314
},
"id": "CVE-2017-9995-b7c4bd99",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/ffmpeg/ffmpeg/commit/7ac5067146613997bb38442cb022d7f41321a706",
"target": {
"file": "libavcodec/scpr.c",
"function": "decompress_i"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "183490693923258289468403565238399367567",
"length": 1249
},
"id": "CVE-2017-9995-e7063d28",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/ffmpeg/ffmpeg/commit/2171dfae8c065878a2e130390eb78cf2947a5b69",
"target": {
"file": "libavcodec/scpr.c",
"function": "decode_unit"
}
}
]
"2026-08-17T05:26:00Z"