漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
FFmpeg 2.1 - 8.1.2 Heap Buffer Overflow via VobSub Subtitle Demuxer
Vulnerability Description
FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
FFmpeg 缓冲区错误漏洞
Vulnerability Description
FFmpeg是FFmpeg组织开源的一套可录制、转换以及流化音视频的完整解决方案。 FFmpeg 2.1版本至8.1.2版本存在缓冲区错误漏洞,该漏洞源于VobSub字幕解复用器存在堆缓冲区溢出问题,允许攻击者通过提供恶意.sub/.idx字幕文件,声明超过libavformat/mpeg.c中固定大小数组边界的流ID,从而导致破坏相邻堆内存。
CVSS Information
N/A
Vulnerability Type
N/A