An inconsistent bits-per-sample value in the ffmpeg4decodepictureheader function in libavcodec/mpeg4videodec.c in FFmpeg 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to a denial of service.
[
{
"source": "https://github.com/ffmpeg/ffmpeg/commit/2fc108f60f98cd00813418a8754a46476b404a3c",
"target": {
"function": "ff_mpeg4_decode_picture_header",
"file": "libavcodec/mpeg4videodec.c"
},
"digest": {
"function_hash": "293953060746545110115995344497464201232",
"length": 4722.0
},
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2018-12459-57d6d724"
},
{
"source": "https://github.com/ffmpeg/ffmpeg/commit/2fc108f60f98cd00813418a8754a46476b404a3c",
"target": {
"file": "libavcodec/mpeg4videodec.c"
},
"digest": {
"line_hashes": [
"276984771347048471388697408929656823427",
"40868172712932210822047402219494391158",
"108981795129314371954512303332135972338"
],
"threshold": 0.9
},
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2018-12459-bd8e4d38"
}
]