CVE-2019-9718
12.03.2019, 09:29
In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ffmpeg | ffmpeg | 3.2 |
| ffmpeg | ffmpeg | 4.1 |
| debian | debian_linux | 9.0 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
| canonical | ubuntu_linux | 19.04 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References