The cdxldecodeframe function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not exclude the CHUNKY format, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
[
{
"id": "CVE-2017-9996-2f0ad500",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"target": {
"file": "libavcodec/cdxl.c",
"function": "cdxl_decode_frame"
},
"digest": {
"function_hash": "232012547363536280629733976652993635058",
"length": 2357.0
},
"source": "https://github.com/ffmpeg/ffmpeg/commit/e1b60aad77c27ed5d4dfc11e5e6a05a38c70489d"
},
{
"id": "CVE-2017-9996-c0e84502",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"target": {
"file": "libavcodec/cdxl.c"
},
"digest": {
"line_hashes": [
"9541136662425234999368121051517161174",
"335429220255434529045940017495389620699",
"282632619432198648312553285132640172496",
"117934805132091481606501704046257057968"
],
"threshold": 0.9
},
"source": "https://github.com/ffmpeg/ffmpeg/commit/e1b60aad77c27ed5d4dfc11e5e6a05a38c70489d"
}
]