The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attackers to cause a denial of service (Out of array read) via an AVI file with crafted dimensions within chroma subsampling data.
{ "vanir_signatures": [ { "source": "https://github.com/ffmpeg/ffmpeg/commit/e724bd1dd9efea3abb8586d6644ec07694afceae", "signature_version": "v1", "deprecated": false, "signature_type": "Function", "target": { "file": "libavcodec/utvideodec.c", "function": "decode_init" }, "digest": { "function_hash": "261170408201920726981716170408581999831", "length": 2014.0 }, "id": "CVE-2018-7557-c58f81bb" }, { "source": "https://github.com/ffmpeg/ffmpeg/commit/e724bd1dd9efea3abb8586d6644ec07694afceae", "signature_version": "v1", "deprecated": false, "signature_type": "Line", "target": { "file": "libavcodec/utvideodec.c" }, "digest": { "line_hashes": [ "214294340827385027346326899809308912278", "319967151764465081227513198959321650619", "160860407430123656188533758835378100984", "88426036291747426103396839917112951526", "322060800242239300558022628811003160243", "294584906807958280719769276673771155382", "173453050150287002342984267387285969060", "28682244462948592149093618534071984159", "105041463035589690360197019114153569694", "112286002592890528022285994238400706647" ], "threshold": 0.9 }, "id": "CVE-2018-7557-e1a439bc" } ] }