CVE-2017-14057
Last modified
CVE-2017-14057 is a vulnerability of currently unknown severity. In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file, which claims a large "name_len" or "count" field in the header but does not contain sufficient backing data, is provided, the loops over the name and markers would consume huge CPU and memory resources, since there is no EOF check inside these loops.. EPSS estimates a 1.81% chance of exploitation in the next 30 days.
Description
In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file, which claims a large "name_len" or "count" field in the header but does not contain sufficient backing data, is provided, the loops over the name and markers would consume huge CPU and memory resources, since there is no EOF check inside these loops.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ffmpeg | Ffmpeg | 3.3.3 |
References
- https://github.com/FFmpeg/FFmpeg/commit/7f9ec5593e04827249e7aeb466da06a98a0d7329Patch, Third Party Advisory
- https://github.com/FFmpeg/FFmpeg/commit/7f9ec5593e04827249e7aeb466da06a98a0d7329Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14057?
How severe is CVE-2017-14057?
How do I fix CVE-2017-14057?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-14050In BlackCat CMS 1.2, backend/addons/install.php allows remot…
- CVE-2017-14051An integer overflow in the qla2x00_sysfs_write_optrom_ctl fu…
- CVE-2017-14053NetApp OnCommand Unified Manager for Clustered Data ONTAP be…
- CVE-2017-14054In libavformat/rmdec.c in FFmpeg 3.3.3, a DoS in ivr_read_he…
- CVE-2017-14055In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_hea…
- CVE-2017-14056In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_head…
- CVE-2017-14058In FFmpeg 2.4 and 3.3.3, the read_data function in libavform…
- CVE-2017-14059In FFmpeg 3.3.3, a DoS in cine_read_header() due to lack of …
- CVE-2017-14060In ImageMagick 7.0.6-10, a NULL Pointer Dereference issue is…
- CVE-2017-14061Integer overflow in the _isBidi function in bidi.c in Libidn…
- CVE-2017-14062Integer overflow in the decode_digit function in puny_decode…9.8
- CVE-2017-14063Async Http Client (aka async-http-client) before 2.0.35 can …
Are you affected by CVE-2017-14057?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
