CVE-2019-12730

aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-06-04 14:29

Updated : 2023-12-10 12:59


NVD link : CVE-2019-12730

Mitre link : CVE-2019-12730

CVE.ORG link : CVE-2019-12730


JSON object : View

Products Affected

ffmpeg

  • ffmpeg
CWE
CWE-908

Use of Uninitialized Resource