The cdxldecodeframe function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not exclude the CHUNKY format, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
[
{
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/e1b60aad77c27ed5d4dfc11e5e6a05a38c70489d",
"id": "CVE-2017-9996-2f0ad500",
"signature_version": "v1",
"target": {
"function": "cdxl_decode_frame",
"file": "libavcodec/cdxl.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "232012547363536280629733976652993635058",
"length": 2357.0
}
},
{
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/1e42736b95065c69a7481d0cf55247024f54b660",
"id": "CVE-2017-9996-7fcd8b63",
"signature_version": "v1",
"target": {
"file": "libavcodec/cdxl.c"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"253968693662442934354663313725314224920",
"155954498066262174679898175888474969919",
"271068582030536723487794266941703843721",
"22086510837230335350562603478408771661"
]
}
},
{
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/e1b60aad77c27ed5d4dfc11e5e6a05a38c70489d",
"id": "CVE-2017-9996-c0e84502",
"signature_version": "v1",
"target": {
"file": "libavcodec/cdxl.c"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"9541136662425234999368121051517161174",
"335429220255434529045940017495389620699",
"282632619432198648312553285132640172496",
"117934805132091481606501704046257057968"
]
}
},
{
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/1e42736b95065c69a7481d0cf55247024f54b660",
"id": "CVE-2017-9996-cf24cf4d",
"signature_version": "v1",
"target": {
"function": "cdxl_decode_frame",
"file": "libavcodec/cdxl.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "218522419038422982971272059869302486306",
"length": 2384.0
}
}
]