An issue was discovered in the FFmpeg package, where vp3decodeframe in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.
[
{
"id": "CVE-2022-3109-2009719d",
"target": {
"file": "libavcodec/vp3.c"
},
"digest": {
"line_hashes": [
"296668209892502617258083696776298184501",
"179955415149809112259535756720552300062",
"234635089860816423356759960037085279787",
"223938992080501052778109654229955851693",
"114824492263024678544587325202192976403"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/656cb0450aeb73b25d7d26980af342b37ac4c568",
"signature_type": "Line"
},
{
"id": "CVE-2022-3109-6328b518",
"target": {
"function": "vp3_decode_frame",
"file": "libavcodec/vp3.c"
},
"digest": {
"length": 7000.0,
"function_hash": "227388434592210151558034273051090982660"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/656cb0450aeb73b25d7d26980af342b37ac4c568",
"signature_type": "Function"
}
]