aareadheader in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
{ "vanir_signatures": [ { "id": "CVE-2019-12730-7ad01a8b", "deprecated": false, "signature_version": "v1", "digest": { "function_hash": "305169126962415473109063619773134354271", "length": 5010.0 }, "signature_type": "Function", "source": "https://github.com/ffmpeg/ffmpeg/commit/ed188f6dcdf0935c939ed813cf8745d50742014b", "target": { "function": "aa_read_header", "file": "libavformat/aadec.c" } }, { "id": "CVE-2019-12730-e5625f16", "deprecated": false, "signature_version": "v1", "digest": { "line_hashes": [ "230500099609806479454228911954939380534", "55508316595384027820348845657613488910", "136035362049246924189988944707562497944", "186174122281508782842403234461208723560", "326608014915734517485433510337139725250", "194489080888257855335467963784983309771", "338138698210939380158150647791524521621", "287571495035033928328411216777340090608", "291559305924628784409449412815549265630" ], "threshold": 0.9 }, "signature_type": "Line", "source": "https://github.com/ffmpeg/ffmpeg/commit/ed188f6dcdf0935c939ed813cf8745d50742014b", "target": { "file": "libavformat/aadec.c" } } ] }