Skip to main content

Numeric Errors

CVE-2015-8364

Severity High
Score 7.3/10

Summary

Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg 0.6 prior to 2.4.12, 2.5.x prior to 2.5.9, 2.6.x prior to 2.6.5, 2.7.x prior to 2.7.3, and 2.8.x prior to 2.8.3, 2.9-dev allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via crafted image dimensions in Indeo Video Interactive data.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • LOW

CWE-189 - Numeric Errors

Weaknesses in this category are related to improper calculation or conversion of numbers.

Advisory Timeline

  • Published