{"id":"CVE-2017-14169","details":"In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -\u003e 2.4, an integer signedness error might occur when a crafted file, which claims a large \"item_num\" field such as 0xffffffff, is provided. As a result, the variable \"item_num\" turns negative, bypassing the check for a large value.","modified":"2026-05-07T04:39:31.621574Z","published":"2017-09-07T06:29:00.187Z","related":["openSUSE-SU-2024:10754-1"],"database_specific":{"unresolved_ranges":[{"cpe":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"9.0"}],"source":"CPE_FIELD"}]},"references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3996"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/100692"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/02/msg00005.html"},{"type":"FIX","url":"https://github.com/FFmpeg/FFmpeg/commit/9d00fb9d70ee8c0cc7002b89318c5be00f1bbdad"},{"type":"FIX","url":"https://github.com/FFmpeg/FFmpeg/commit/a4e85b2e1c8d5b4bf0091157bbdeb0e457fb7b8f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ffmpeg/ffmpeg","events":[{"introduced":"0"},{"last_affected":"771274876a5726f11bac5ae55de94d041cadf4c9"},{"last_affected":"a4044e04486d1136022498891088a90baf5b2775"}],"database_specific":{"cpe":["cpe:2.3:a:ffmpeg:ffmpeg:3.3.3:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"3.3.3"},{"last_affected":"8.0"}],"source":"CPE_FIELD"}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-14169.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}