In FFmpeg 4.0.1, a missing check for failure of a call to initgetbits8() in the avprivac3parseheader function in libavcodec/ac3parser.c may trigger a NULL pointer dereference while converting a crafted AVI file to MPEG4, leading to a denial of service.
{ "vanir_signatures": [ { "digest": { "length": 375.0, "function_hash": "142391142906413682480041211024204642092" }, "target": { "file": "libavcodec/ac3_parser.c", "function": "avpriv_ac3_parse_header" }, "deprecated": false, "source": "https://github.com/ffmpeg/ffmpeg/commit/00e8181bd97c834fe60751b0c511d4bb97875f78", "signature_version": "v1", "id": "CVE-2018-13303-44c73212", "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "212924937453151307161016188838557761501", "43197743373531770406142050929992758697", "336388221455771699703553060708214641660", "184902950246473843971472263661582995389" ] }, "target": { "file": "libavcodec/ac3_parser.c" }, "deprecated": false, "source": "https://github.com/ffmpeg/ffmpeg/commit/00e8181bd97c834fe60751b0c511d4bb97875f78", "signature_version": "v1", "id": "CVE-2018-13303-a1c2a195", "signature_type": "Line" } ] }