UBUNTU-CVE-2017-14171
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-14171
Summary:
Details: In libavformat/nsvdec.c in FFmpeg 2.4 and 3.3.3, a DoS in nsv_parse_NSVf_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted NSV file, which claims a large "table_entries_used" field in the header but does not contain sufficient backing data, is provided, the loop over 'table_entries_used' would consume huge CPU resources, since there is no EOF check inside the loop.
References: https://ubuntu.com/security/CVE-2017-14171, https://github.com/FFmpeg/FFmpeg/commit/c24bcb553650b91e9eff15ef6e54ca73de2453b7, https://www.cve.org/CVERecord?id=CVE-2017-14171
Affected packages
Package
Name: ffmpeg
Purl: pkg:deb/ubuntu/ffmpeg@7:2.8.14-0ubuntu0.16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
