mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-27 02:02:23 +02:00
18 lines
818 B
Markdown
18 lines
818 B
Markdown
### [CVE-2021-3566](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3566)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that references an image, followed by a file the triggers the tty demuxer, the contents of the second file will be copied into the output file verbatim (as long as the `-vcodec copy` option is passed to ffmpeg).
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
No PoCs from references.
|
|
|
|
#### Github
|
|
- https://github.com/akaganeite/CVE4PP
|
|
|