FFmpeg
Heap out-of-bounds write in the CFHD decoder via AVI demuxingDetails
Summary
FFmpeg 4.4 through versions before 9.0 failed to enforce the CFHD transform-type-2 output-width invariant. A crafted AVI file could make reconstruction write oversized sample rows beyond the output frame, enabling heap corruption and potentially arbitrary code execution.
Disclosure timeline
- Reported the vulnerability to the FFmpeg security team.
- Fix pull request created.
- Fix pull request merged.
- Requested a CVE through VulnCheck.
- CVE published.