Candidate: CVE-2017-9996
PublicDate: 2017-06-28
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9996
 https://github.com/FFmpeg/FFmpeg/commit/1e42736b95065c69a7481d0cf55247024f54b660
 https://github.com/FFmpeg/FFmpeg/commit/e1b60aad77c27ed5d4dfc11e5e6a05a38c70489d
 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=1378
 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=1427
Description:
 The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before
 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and
 3.3.x before 3.3.1 does not exclude the CHUNKY format, which allows remote
 attackers to cause a denial of service (heap-based buffer overflow and
 application crash) or possibly have unspecified other impact via a crafted
 file.
Ubuntu-Description:
Notes:
Bugs:
Priority: medium
Discovered-by:
Assigned-to:

Patches_libav:
upstream_libav: needs-triage
precise/esm_libav: DNE
trusty_libav: needed
vivid/ubuntu-core_libav: DNE
xenial_libav: DNE
yakkety_libav: DNE
zesty_libav: DNE
artful_libav: DNE
devel_libav: DNE

Patches_ffmpeg:
Priority_ffmpeg: low
upstream_ffmpeg: released (7:3.2.5-1)
precise/esm_ffmpeg: DNE
trusty_ffmpeg: DNE
vivid/ubuntu-core_ffmpeg: DNE
xenial_ffmpeg: needed
yakkety_ffmpeg: ignored (reached end-of-life)
zesty_ffmpeg: needed
artful_ffmpeg: not-affected (7:3.2.6-1)
devel_ffmpeg: not-affected (7:3.2.6-1)
