CVE-2015-3395
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via a crafted image, related to a pixel pointer, which triggers an out-of-bounds array access.
La función msrle_decode_pal4 en msrledec.c en Libav anterior a 10.7 y 11.x anterior a 11.4 y FFmpeg anterior a 2.0.7, 2.2.x anterior a 2.2.15, 2.4.x anterior a 2.4.8, 2.5.x anterior a 2.5.6, y 2.6.x anterior a 2.6.2 permite a atacantes remotos tener un impacto no especificado a través de una imagen manipulada, relacionado con un puntero de pixels, lo que provoca un acceso a array fuera de rango.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-04-21 CVE Reserved
- 2015-06-15 CVE Published
- 2023-11-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=f7e1367f58263593e6cee3c282f7277d7ee9d553 | X_refsource_confirm | |
http://www.securityfocus.com/bid/74433 | Vdb Entry | |
https://git.libav.org/?p=libav.git%3Ba=blob%3Bf=Changelog%3Bhb=refs/tags/v11.4 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2015/dsa-3288 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-2944-1 | 2023-11-07 | |
https://security.gentoo.org/glsa/201603-06 | 2023-11-07 | |
https://security.gentoo.org/glsa/201705-08 | 2023-11-07 | |
https://www.ffmpeg.org/security.html | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.04" | lts |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.0.6 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.0.6" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.0 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.0" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.1 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.1" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.2 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.2" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.3 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.3" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.4 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.4" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.5 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.5" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.6 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.6" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.7 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.7" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.8 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.8" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.9 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.9" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.10 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.10" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.11 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.11" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.12 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.12" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.13 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.13" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.2.14 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.2.14" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.4.0 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.4.0" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.4.1 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.4.1" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.4.2 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.4.2" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.4.3 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.4.3" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.4.4 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.4.4" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.4.5 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.4.5" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.4.6 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.4.6" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.4.7 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.4.7" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.5.0 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.5.0" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.5.1 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.5.1" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.5.2 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.5.2" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.5.3 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.5.3" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.5.4 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.5.4" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.5.5 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.5.5" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.6.0 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.6.0" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.6.1 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.6.1" | - |
Affected
| ||||||
Libav Search vendor "Libav" | Libav Search vendor "Libav" for product "Libav" | <= 10.6 Search vendor "Libav" for product "Libav" and version " <= 10.6" | - |
Affected
| ||||||
Libav Search vendor "Libav" | Libav Search vendor "Libav" for product "Libav" | 11.0 Search vendor "Libav" for product "Libav" and version "11.0" | - |
Affected
| ||||||
Libav Search vendor "Libav" | Libav Search vendor "Libav" for product "Libav" | 11.1 Search vendor "Libav" for product "Libav" and version "11.1" | - |
Affected
| ||||||
Libav Search vendor "Libav" | Libav Search vendor "Libav" for product "Libav" | 11.2 Search vendor "Libav" for product "Libav" and version "11.2" | - |
Affected
| ||||||
Libav Search vendor "Libav" | Libav Search vendor "Libav" for product "Libav" | 11.3 Search vendor "Libav" for product "Libav" and version "11.3" | - |
Affected
|