CVE-2017-14171: Ffmpeg

Medium severity, CVSS 6.5. EPSS: 1.8% chance of exploitation in the next 30 days.

In libavformat/nsvdec.c in FFmpeg 2.4 and 3.3.3, a DoS in nsv_parse_NSVf_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted NSV file, which claims a large "table_entries_used" field in the header but does not contain sufficient backing data, is provided, the loop over 'table_entries_used' would consume huge CPU resources, since there is no EOF check inside the loop.

Affected products

  • Ffmpeg Ffmpeg: version 3.3.3 only

Published 2017-09-07. Last modified 2026-06-17.