An improper integer type in the mpeg4encodegop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to a denial of service.
{ "vanir_signatures": [ { "id": "CVE-2018-12458-0c34ef7e", "digest": { "threshold": 0.9, "line_hashes": [ "56833795360251818369765033581323091741", "280404874225817245952846567227135081635", "54896246386035839919929168273124326120", "287697360365446967200998116568866649071" ] }, "signature_type": "Line", "target": { "file": "libavcodec/mpeg4videoenc.c" }, "deprecated": false, "signature_version": "v1", "source": "https://github.com/ffmpeg/ffmpeg/commit/e1182fac1afba92a4975917823a5f644bee7e6e8" }, { "id": "CVE-2018-12458-649dec09", "digest": { "threshold": 0.9, "line_hashes": [ "56833795360251818369765033581323091741", "280404874225817245952846567227135081635", "54896246386035839919929168273124326120", "287697360365446967200998116568866649071" ] }, "signature_type": "Line", "target": { "file": "libavcodec/mpeg4videoenc.c" }, "deprecated": false, "signature_version": "v1", "source": "https://github.com/ffmpeg/ffmpeg/commit/6bbef938839adc55e8e048bc9cc2e0fafe2064df" } ] }