CVE-2015-3417: Debian Linux

Medium severity, CVSS 6.8. EPSS: 2.6% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstrated by an HTML VIDEO element that references H.264 data.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Ffmpeg Ffmpeg: up to and including 2.3.5

Published 2015-04-24. Last modified 2026-06-17.