CVE-2014-9676

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/02/2015
Last modified:
12/04/2025

Description

The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote attackers to cause a denial of service ("invalid memory handler") and possibly execute arbitrary code via a crafted video that triggers a use after free.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* 2.1.4 (including)