Back to search
CVE-2016-10190
Published: Feb 9, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[debian-lts-announce] 20181220 [SECURITY] [DLA 1611-1] libav security update
mailing-list
x_refsource_MLIST
[oss-security] 20170201 CVE Request: ffmpeg remote exploitaion results code execution
mailing-list
x_refsource_MLIST
[oss-security] 20170202 Re: CVE Request: ffmpeg remote exploitaion results code execution
mailing-list
x_refsource_MLIST
https://trac.ffmpeg.org/ticket/5992
x_refsource_CONFIRM
95986
vdb-entry
x_refsource_BID
https://ffmpeg.org/security.html
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now