DoS Vulnerability in FFmpeg 3.3.3: CPU and Memory Consumption in cine_read_header()

DoS Vulnerability in FFmpeg 3.3.3: CPU and Memory Consumption in cine_read_header()

CVE-2017-14059 · HIGH Severity

AV:N/AC:M/AU:N/C:N/I:N/A:C

In FFmpeg 3.3.3, a DoS in cine_read_header() due to lack of an EOF check might cause huge CPU and memory consumption. When a crafted CINE file, which claims a large "duration" field in the header but does not contain sufficient backing data, is provided, the image-offset parsing loop would consume huge CPU and memory resources, since there is no EOF check inside the loop.

Learn more about our Web Application Penetration Testing UK.