Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2017/10/20/4 | mailing list third party advisory patch |
http://www.securityfocus.com/bid/101518 | vdb entry third party advisory |
https://www.debian.org/security/2017/dsa-4049 | vendor advisory |