SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-3417

Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as…

MEDIUM 6.8EPSS 2.55%

Does this matter?

Lower severity and a low EPSS score (2.55%). Track it; it rarely justifies an emergency change on its own.

Description

Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
2.55% probability · 84th percentile
CISA KEV
Not listed
Affected
ffmpeg/ffmpeg · debian/debian linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.