In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DSA-4449-1 | ffmpeg security update |
![]() |
EUVD-2019-19083 | In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex format argument to sscanf. |
![]() |
USN-3967-1 | FFmpeg vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:01:53.269Z
Reserved: 2019-03-12T00:00:00
Link: CVE-2019-9718

No data.

Status : Modified
Published: 2019-03-12T09:29:00.530
Modified: 2024-11-21T04:52:10.140
Link: CVE-2019-9718


No data.