← Back

CVE-2015-3395

nvd nist
Published: Jun 16, 2015Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via a crafted image, related to a pixel pointer, which triggers an out-of-bounds array access.

Affected (38)

1 product
Ubuntu Linux
1 product
Ffmpeg
1 product
Libav
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.04
Configuration B
32 vulnerable
Vulnerable SoftwareAffected Versions
Ffmpeg
Version 2.0.6
Version 2.2.0
Version 2.2.10
Version 2.2.11
Version 2.2.12
Version 2.2.13
Version 2.2.14
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.2.4
Version 2.2.5
Version 2.2.6
Version 2.2.7
Version 2.2.8
Version 2.2.9
Version 2.4.0
Version 2.4.1
Version 2.4.2
Version 2.4.3
Version 2.4.4
Version 2.4.5
Version 2.4.6
Version 2.4.7
Version 2.5.0
Version 2.5.1
Version 2.5.2
Version 2.5.3
Version 2.5.4
Version 2.5.5
Version 2.6.0
Version 2.6.1
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
Libav
Up to 10.6
Version 11.0
Version 11.1
Version 11.2
Version 11.3

References (16)

Timeline

No history available yet.