CVE-2017-14169

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
07/09/2017
Last modified:
20/04/2025

Description

In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, which claims a large "item_num" field such as 0xffffffff, is provided. As a result, the variable "item_num" turns negative, bypassing the check for a large value.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ffmpeg:ffmpeg:3.3.3:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*