CVE-2019-11338

Source
https://cve.org/CVERecord?id=CVE-2019-11338
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-11338.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-11338
Downstream
Related
Published
2019-04-19T00:29:00.230Z
Modified
2026-02-08T04:15:42.817456Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.

References

Affected packages

Git / git.ffmpeg.org/ffmpeg.git

Affected ranges

Type
GIT
Repo
https://git.ffmpeg.org/ffmpeg.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-11338.json"

Git / github.com/ffmpeg/ffmpeg

Affected ranges

Type
GIT
Repo
https://github.com/ffmpeg/ffmpeg
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

Other
N
n0.*
n0.11-dev
n0.12-dev
n0.8
n1.*
n1.1-dev
n1.2-dev
n1.3-dev
n2.*
n2.0
n2.1-dev
n2.2-dev
n2.3-dev
n2.4-dev
n2.5-dev
n2.6-dev
n2.7-dev
n2.8-dev
n2.9-dev
n3.*
n3.1-dev
n3.2-dev
n3.3-dev
n3.4
n3.4-dev
n3.4.1
n3.4.2
n3.4.3
n3.4.4
n3.4.5
n3.5-dev
n4.*
n4.1-dev
n4.2-dev

Database specific

vanir_signatures
[
    {
        "signature_type": "Function",
        "source": "https://github.com/ffmpeg/ffmpeg/commit/9ccc633068c6fe76989f487c8932bd11886ad65b",
        "target": {
            "file": "libavcodec/hevcdec.c",
            "function": "decode_nal_unit"
        },
        "id": "CVE-2019-11338-27b24530",
        "signature_version": "v1",
        "digest": {
            "function_hash": "45059981939637157877700820184160513142",
            "length": 3748.0
        },
        "deprecated": false
    },
    {
        "signature_type": "Line",
        "source": "https://github.com/ffmpeg/ffmpeg/commit/54655623a82632e7624714d7b2a3e039dc5faa7e",
        "target": {
            "file": "libavcodec/hevcdec.c"
        },
        "id": "CVE-2019-11338-2ff1770d",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "167280379000740045495955150237615756625",
                "217014810008278832315784870144539884880",
                "275342592106358026505968957521723311896",
                "93282334362186985464861588891659759283",
                "20102417044240740358849022761902872871",
                "315077692536051889598880836078603069425",
                "70136499457010029194053811280640163862",
                "143535213550679828004584463617263301076",
                "128790428654206636083008055072316941250",
                "317589072920574188696555524382694908121",
                "230507251567370162258824489236627234082",
                "326752629143355640910394448450558654154",
                "272291046614698887552076985666997168650",
                "184162110970024235939528314086827681328",
                "138312105946242993354180976917596471857"
            ]
        },
        "deprecated": false
    },
    {
        "signature_type": "Function",
        "source": "https://github.com/ffmpeg/ffmpeg/commit/9ccc633068c6fe76989f487c8932bd11886ad65b",
        "target": {
            "file": "libavcodec/hevcdec.c",
            "function": "hls_slice_header"
        },
        "id": "CVE-2019-11338-50b395ac",
        "signature_version": "v1",
        "digest": {
            "function_hash": "331539604942389623747355164843225661104",
            "length": 14167.0
        },
        "deprecated": false
    },
    {
        "signature_type": "Function",
        "source": "https://github.com/ffmpeg/ffmpeg/commit/54655623a82632e7624714d7b2a3e039dc5faa7e",
        "target": {
            "file": "libavcodec/hevcdec.c",
            "function": "decode_nal_unit"
        },
        "id": "CVE-2019-11338-57cefee5",
        "signature_version": "v1",
        "digest": {
            "function_hash": "267982237115177009869281056395071073673",
            "length": 5011.0
        },
        "deprecated": false
    },
    {
        "signature_type": "Function",
        "source": "https://github.com/ffmpeg/ffmpeg/commit/54655623a82632e7624714d7b2a3e039dc5faa7e",
        "target": {
            "file": "libavcodec/hevcdec.c",
            "function": "hls_slice_header"
        },
        "id": "CVE-2019-11338-70732dfc",
        "signature_version": "v1",
        "digest": {
            "function_hash": "79026117247124224733924662327854734242",
            "length": 14204.0
        },
        "deprecated": false
    },
    {
        "signature_type": "Line",
        "source": "https://github.com/ffmpeg/ffmpeg/commit/9ccc633068c6fe76989f487c8932bd11886ad65b",
        "target": {
            "file": "libavcodec/hevcdec.c"
        },
        "id": "CVE-2019-11338-f5c87da6",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "167280379000740045495955150237615756625",
                "217014810008278832315784870144539884880",
                "275342592106358026505968957521723311896",
                "93282334362186985464861588891659759283",
                "20102417044240740358849022761902872871",
                "247604245573560918611417214280701552476",
                "203456488689133841884968569597706019293",
                "226504480904387125210540704722477978516",
                "230507251567370162258824489236627234082",
                "326752629143355640910394448450558654154",
                "272291046614698887552076985666997168650",
                "184162110970024235939528314086827681328",
                "138312105946242993354180976917596471857"
            ]
        },
        "deprecated": false
    }
]
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-11338.json"