CVE-2019-1000016

NameCVE-2019-1000016
DescriptionFFMPEG version 4.1 contains a CWE-129: Improper Validation of Array Index vulnerability in libavcodec/cbs_av1.c that can result in Denial of service. This attack appears to be exploitable via specially crafted AV1 file has to be provided as input. This vulnerability appears to have been fixed in after commit b97a4b658814b2de8b9f2a3bce491c002d34de31.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs922066

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ffmpeg (PTS)stretch (security)7:3.2.18-0+deb9u1fixed
stretch (lts), stretch7:3.2.19-0+deb9u4fixed
buster7:4.1.9-0+deb10u1fixed
buster (security)7:4.1.11-0+deb10u1fixed
bullseye7:4.3.6-0+deb11u1fixed
bullseye (security)7:4.3.7-0+deb11u1fixed
bookworm (security), bookworm7:5.1.5-0+deb12u1fixed
trixie7:6.1.1-4fixed
sid7:6.1.1-5fixed
libav (PTS)jessie, jessie (lts)6:11.12-1~deb8u9fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ffmpegsourcestretch(not affected)
ffmpegsource(unstable)7:4.1.1-1low922066
libavsourcewheezy(unfixed)end-of-life
libavsourcejessie(not affected)
libavsource(unstable)(unfixed)

Notes

[stretch] - ffmpeg <not-affected> (Vulnerable code not present)
https://github.com/FFmpeg/FFmpeg/commit/b97a4b658814b2de8b9f2a3bce491c002d34de31#diff-cd7e24986650014d67f484f3ffceef3f
[jessie] - libav <not-affected> (Vulnerable code not present)

Search for package or bug name: Reporting problems