CVE-2022-3965
ffmpeg QuickTime Graphics Video Encoder smcenc.c smc_encode_stream out-of-bounds
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream of the file libavcodec/smcenc.c of the component QuickTime Graphics Video Encoder. The manipulation of the argument y_size leads to out-of-bounds read. The attack can be initiated remotely. The name of the patch is 13c13109759090b7f7182480d075e13b36ed8edd. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213544.
Una vulnerabilidad fue encontrada en ffmpeg y clasificada como problemática. Esta vulnerabilidad afecta a la función smc_encode_stream del archivo libavcodec/smcenc.c del componente QuickTime Graphics Video Encoder. La manipulación del argumento y_size conduce a una lectura fuera de límites. El ataque se puede iniciar de forma remota. El nombre del parche es 13c13109759090b7f7182480d075e13b36ed8edd. Se recomienda aplicar un parche para solucionar este problema. El identificador de esta vulnerabilidad es VDB-213544.
It was discovered that FFmpeg could be made to dereference a null pointer. An attacker could possibly use this to cause a denial of service via application crash. These issues only affected Ubuntu 16.04 ESM, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. It was discovered that FFmpeg could be made to access an out-of-bounds frame by the Apple RPZA encoder. An attacker could possibly use this to cause a denial of service via application crash or access sensitive information. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.10.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-13 CVE Reserved
- 2022-11-13 CVE Published
- 2024-08-03 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/13c13109759090b7f7182480d075e13b36ed8edd | 2023-12-23 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/202312-14 | 2023-12-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | >= 5.0 < 5.0.3 Search vendor "Ffmpeg" for product "Ffmpeg" and version " >= 5.0 < 5.0.3" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | >= 5.1 < 5.1.3 Search vendor "Ffmpeg" for product "Ffmpeg" and version " >= 5.1 < 5.1.3" | - |
Affected
|