In FFmpeg 4.0.1, a missing check for failure of a call to initgetbits8() in the avprivac3parseheader function in libavcodec/ac3parser.c may trigger a NULL pointer dereference while converting a crafted AVI file to MPEG4, leading to a denial of service.
[
{
"digest": {
"length": 375.0,
"function_hash": "142391142906413682480041211024204642092"
},
"target": {
"function": "avpriv_ac3_parse_header",
"file": "libavcodec/ac3_parser.c"
},
"signature_type": "Function",
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/00e8181bd97c834fe60751b0c511d4bb97875f78",
"signature_version": "v1",
"id": "CVE-2018-13303-44c73212"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"212924937453151307161016188838557761501",
"43197743373531770406142050929992758697",
"336388221455771699703553060708214641660",
"184902950246473843971472263661582995389"
]
},
"target": {
"file": "libavcodec/ac3_parser.c"
},
"signature_type": "Line",
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/00e8181bd97c834fe60751b0c511d4bb97875f78",
"signature_version": "v1",
"id": "CVE-2018-13303-a1c2a195"
}
]