Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.
[
{
"id": "CVE-2017-9992-60fa412b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "173690714667852622426013926318516017828",
"length": 1168.0
},
"target": {
"file": "libavcodec/dfa.c",
"function": "decode_dds1"
},
"source": "https://github.com/ffmpeg/ffmpeg/commit/f52fbf4f3ed02a7d872d8a102006f29b4421f360"
},
{
"id": "CVE-2017-9992-a8b5c31e",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"line_hashes": [
"49292181257551172576771973708726667050",
"51557325619138272839030920394370860057",
"143321983408069829629295156302111297253",
"168494076503263253939609218673331973402"
],
"threshold": 0.9
},
"target": {
"file": "libavcodec/dfa.c"
},
"source": "https://github.com/ffmpeg/ffmpeg/commit/f52fbf4f3ed02a7d872d8a102006f29b4421f360"
}
]