{ "schema_version": "1.4.0", "id": "GHSA-x452-h4mp-43c7", "modified": "2025-04-12T12:51:39Z", "published": "2022-05-14T01:46:18Z", "aliases": [ "CVE-2015-6820" ], "details": "The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not check for a matching AAC frame syntax element before proceeding with Spectral Band Replication calculations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted AAC data.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-6820" }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2018/12/msg00009.html" }, { "type": "WEB", "url": "http://ffmpeg.org/security.html" }, { "type": "WEB", "url": "http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=79a98294da6cd85f8c86b34764c5e0c43b09eea3" }, { "type": "WEB", "url": "http://git.videolan.org/?p=ffmpeg.git;a=commit;h=79a98294da6cd85f8c86b34764c5e0c43b09eea3" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1033483" }, { "type": "WEB", "url": "http://www.ubuntu.com/usn/USN-2944-1" } ], "database_specific": { "cwe_ids": [ "CWE-119" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2015-09-06T02:59:00Z" } }