adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step because the second argument to init_get_bits can be crafted.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-08-21T00:00:00

Updated: 2024-08-04T01:37:16.217Z

Reserved: 2021-08-07T00:00:00

Link: CVE-2021-38171

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-21T17:15:07.700

Modified: 2024-11-21T06:16:33.257

Link: CVE-2021-38171

cve-icon Redhat

No data.