REDHAT-BUG-2458764: Integer Overflow
A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment reassembly bounds checks, leading to a heap out-of-bounds write. Successful exploitation can result in a denial of service (DoS) due to an application crash, and potentially lead to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2458764?
The severity of REDHAT-BUG-2458764 is considered critical due to the potential for remote code execution.
How do I fix REDHAT-BUG-2458764?
To fix REDHAT-BUG-2458764, update FFmpeg to the latest version that addresses this vulnerability.
What types of attacks can exploit REDHAT-BUG-2458764?
A remote attacker can exploit REDHAT-BUG-2458764 by delivering a malicious MPEG-PS/VOB media file containing a harmful DVD subtitle stream.
Which versions of FFmpeg are affected by REDHAT-BUG-2458764?
The specific versions of FFmpeg affected by REDHAT-BUG-2458764 include those prior to the patch release that addresses the signed integer overflow issue.
What is the primary cause of the vulnerability REDHAT-BUG-2458764?
The primary cause of REDHAT-BUG-2458764 is a signed integer overflow in the fragment reassembly bounds checks of the DVD subtitle parser.