The ff_er_frame_end function in libavcodec/error_resilience.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 does not properly verify that a frame is fully initialized, which allows remote attackers to trigger a NULL pointer dereference via crafted picture data.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < 05d43455f6bffa6abc7b937ca58be00452e6973f |