In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file, which claims a large "name_len" or "count" field in the header but does not contain sufficient backing data, is provided, the loops over the name and markers would consume huge CPU and memory resources, since there is no EOF check inside these loops.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-08-31T15:00:00
Updated: 2024-08-05T19:13:41.757Z
Reserved: 2017-08-31T00:00:00
Link: CVE-2017-14057
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-08-31T15:29:00.420
Modified: 2024-11-21T03:12:03.850
Link: CVE-2017-14057
Redhat
No data.