CVE-2021-38171 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Insufficient validation |
Description | adts_decode_extradata in libavformat/adtsenc.c in FFmpeg before version 4.4.1 does not check the init_get_bits return value, which is a necessary step because the second argument to init_get_bits can be crafted. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-1989 | ffmpeg | 2:4.4-6 | 2:4.4.1-1 | Medium | Fixed |