In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ffhtmlmarkupto_ass in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.
[
{
"digest": {
"length": 3632.0,
"function_hash": "134429341697870814247987316111924007456"
},
"signature_version": "v1",
"id": "CVE-2019-9718-755ab778",
"target": {
"file": "libavcodec/htmlsubtitles.c",
"function": "ff_htmlmarkup_to_ass"
},
"signature_type": "Function",
"source": "https://github.com/ffmpeg/ffmpeg/commit/23ccf3cabb4baf6e8af4b1af3fcc59c904736f21",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"146229409084369695006291932218330531278",
"186871920662715219977446106701134555870",
"310562769026243982809424482522257025845",
"34344457376983665913898773828430549216",
"260166848363255873671710857472511837215",
"80024346695892532889397988976103392180",
"202968329324838149850240999019982554458"
]
},
"signature_version": "v1",
"id": "CVE-2019-9718-da1a4911",
"target": {
"file": "libavcodec/htmlsubtitles.c"
},
"signature_type": "Line",
"source": "https://github.com/ffmpeg/ffmpeg/commit/23ccf3cabb4baf6e8af4b1af3fcc59c904736f21",
"deprecated": false
}
]