CVE-2015-3417
EPSS 1.0%
Description
Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.
How to fix CVE-2015-3417
To remediate CVE-2015-3417, upgrade the affected package to a fixed version below.
- Debian/ffmpeg—upgrade to 7:2.6.1-1 or later
Is CVE-2015-3417 being exploited?
Low — EPSS is 1.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 7:2.6.1-1