libavformat/movenc.c in FFmpeg before 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted Waveform audio file.
{ "vanir_signatures": [ { "target": { "file": "libavformat/movenc.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "306182149830260832260979441198774379409", "171070650195834199310586500933145057113", "87481129932226713652919553000304522214" ] }, "signature_type": "Line", "signature_version": "v1", "deprecated": false, "id": "CVE-2018-14394-6c6703d0", "source": "https://github.com/ffmpeg/ffmpeg/commit/3a2d21bc5f97aa0161db3ae731fc2732be6108b8" }, { "target": { "file": "libavformat/movenc.c", "function": "ff_mov_write_packet" }, "digest": { "function_hash": "293118525475458948957410842096893374496", "length": 7968.0 }, "signature_type": "Function", "signature_version": "v1", "deprecated": false, "id": "CVE-2018-14394-ddedcd94", "source": "https://github.com/ffmpeg/ffmpeg/commit/3a2d21bc5f97aa0161db3ae731fc2732be6108b8" } ] }