Vulnerability Description
aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ffmpeg | Ffmpeg | < 3.2.14 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/109317
- https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/9b4004c054964a49c7ba44583f4cee22
- https://git.ffmpeg.org/gitweb/ffmpeg.git/shortlog/n4.1.4
- https://github.com/FFmpeg/FFmpeg/commit/ed188f6dcdf0935c939ed813cf8745d50742014bPatchThird Party Advisory
- https://github.com/FFmpeg/FFmpeg/compare/a97ea53...ba11e40Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/30
- https://security.gentoo.org/glsa/202003-65
- https://usn.ubuntu.com/4431-1/
- https://www.debian.org/security/2019/dsa-4502
- http://www.securityfocus.com/bid/109317
- https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/9b4004c054964a49c7ba44583f4cee22
- https://git.ffmpeg.org/gitweb/ffmpeg.git/shortlog/n4.1.4
- https://github.com/FFmpeg/FFmpeg/commit/ed188f6dcdf0935c939ed813cf8745d50742014bPatchThird Party Advisory
- https://github.com/FFmpeg/FFmpeg/compare/a97ea53...ba11e40Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/30
FAQ
What is CVE-2019-12730?
CVE-2019-12730 is a vulnerability with a CVSS score of 9.8 (CRITICAL). aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
How severe is CVE-2019-12730?
CVE-2019-12730 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-12730?
Check the references section above for vendor advisories and patch information. Affected products include: Ffmpeg Ffmpeg.