aareadheader in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
[
{
"deprecated": false,
"id": "CVE-2019-12730-7ad01a8b",
"source": "https://github.com/ffmpeg/ffmpeg/commit/ed188f6dcdf0935c939ed813cf8745d50742014b",
"digest": {
"function_hash": "305169126962415473109063619773134354271",
"length": 5010.0
},
"target": {
"function": "aa_read_header",
"file": "libavformat/aadec.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2019-12730-e5625f16",
"source": "https://github.com/ffmpeg/ffmpeg/commit/ed188f6dcdf0935c939ed813cf8745d50742014b",
"digest": {
"threshold": 0.9,
"line_hashes": [
"230500099609806479454228911954939380534",
"55508316595384027820348845657613488910",
"136035362049246924189988944707562497944",
"186174122281508782842403234461208723560",
"326608014915734517485433510337139725250",
"194489080888257855335467963784983309771",
"338138698210939380158150647791524521621",
"287571495035033928328411216777340090608",
"291559305924628784409449412815549265630"
]
},
"target": {
"file": "libavformat/aadec.c"
},
"signature_type": "Line",
"signature_version": "v1"
}
]