CVE-2017-14767: Ffmpeg
High severity, CVSS 8.8. EPSS: 2.7% chance of exploitation in the next 30 days.
The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg before 3.3.4 mishandles empty sprop-parameter-sets values, which allows remote attackers to cause a denial of service (heap buffer overflow) or possibly have unspecified other impact via a crafted sdp file.
Affected products
- Ffmpeg Ffmpeg: up to and including 3.3.3
Published 2017-09-27. Last modified 2026-06-17.