{"id":"CVE-2019-17539","details":"In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified other impact when there is no valid close function pointer.","modified":"2026-04-16T04:35:14.938940158Z","published":"2019-10-14T02:15:10.513Z","related":["SUSE-SU-2021:2322-1","SUSE-SU-2021:2929-1","openSUSE-SU-2021:2322-1"],"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/01/msg00026.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202003-65"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4431-1/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2020/dsa-4722"},{"type":"REPORT","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15733"},{"type":"FIX","url":"https://github.com/FFmpeg/FFmpeg/commit/8df6884832ec413cf032dfaa45c23b1c7876670c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ffmpeg/ffmpeg","events":[{"introduced":"0"},{"fixed":"289a79d545e83a97f5cdd00b28ce70638dae53e8"},{"introduced":"ace829cb45cff530b8a0aed6adf18f329d7a98f6"},{"fixed":"26e1d0d015bb11ab0383729c52cfca4fd9cf4e79"},{"introduced":"3c1ecb057d7621e57968624aa15ad3e9efc819f7"},{"fixed":"4521700f295f35da4768f88b570e0836a858ce7b"},{"fixed":"8df6884832ec413cf032dfaa45c23b1c7876670c"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"3.4.7"},{"introduced":"4.0"},{"fixed":"4.0.5"},{"introduced":"4.1"},{"fixed":"4.1.5"}]}}],"versions":["N","n0.11-dev","n0.12-dev","n0.8","n1.1-dev","n1.2-dev","n1.3-dev","n2.0","n2.1-dev","n2.2-dev","n2.3-dev","n2.4-dev","n2.5-dev","n2.6-dev","n2.7-dev","n2.8-dev","n2.9-dev","n3.1-dev","n3.2-dev","n3.3-dev","n3.4","n3.4-dev","n3.4.1","n3.4.2","n3.4.3","n3.4.4","n3.4.5","n3.4.6","n4.0","n4.0.1","n4.0.2","n4.0.3","n4.0.4","n4.1","n4.1-dev","n4.1.1","n4.1.2","n4.1.3","n4.1.4","n4.2-dev"],"database_specific":{"vanir_signatures_modified":"2026-04-11T14:11:12Z","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"9.0"}]},{"events":[{"introduced":"0"},{"last_affected":"10.0"}]},{"events":[{"introduced":"0"},{"last_affected":"16.04"}]},{"events":[{"introduced":"0"},{"last_affected":"18.04"}]},{"events":[{"introduced":"0"},{"last_affected":"20.04"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-17539.json","vanir_signatures":[{"signature_type":"Function","digest":{"length":17416,"function_hash":"205206128562018730369807501325477623210"},"id":"CVE-2019-17539-1794bf98","target":{"function":"avcodec_open2","file":"libavcodec/utils.c"},"source":"https://github.com/ffmpeg/ffmpeg/commit/8df6884832ec413cf032dfaa45c23b1c7876670c","signature_version":"v1","deprecated":false},{"signature_type":"Line","target":{"file":"libavcodec/utils.c"},"id":"CVE-2019-17539-64ec3124","digest":{"line_hashes":["220330626061826535315657386462474702952","284434091912125655641126633699664364654","169031453947109328122480615508055499488","274679704614273153990806559594132734773"],"threshold":0.9},"source":"https://github.com/ffmpeg/ffmpeg/commit/8df6884832ec413cf032dfaa45c23b1c7876670c","signature_version":"v1","deprecated":false},{"signature_type":"Function","digest":{"length":3260,"function_hash":"319021067119698628255415066517927384702"},"id":"CVE-2019-17539-89be5de9","target":{"function":"hls_write_trailer","file":"libavformat/hlsenc.c"},"signature_version":"v1","source":"https://github.com/ffmpeg/ffmpeg/commit/4521700f295f35da4768f88b570e0836a858ce7b","deprecated":false},{"signature_type":"Line","digest":{"line_hashes":["111757355275855299767214097555503833425","332776709410158749058424084520384076278","126244308190247979754930455471757737376","94499542832375321740817633492542024465","130172128018366235132297832589555939800","55536100370799741404976270153852322799","178437194551693198799431818210633522790","212929257175167450126831190360563960264","62370169604886578115909868256949237475","129049294233240527051413687895358407876","286287738882113096420417966736547438098","243635147339143298832966112516759698288","272776886790752221810033028800273149150","9747124137513848496923527654951202606","301927968725738236165575381671008622991","192183203489963350993466951267713113650","122011600157872378775713225314617790943","25213801080174912976460312183375057971","74233774275043259138930394312098586340","241426111203459057517320451984683680334","255987871053178237141709543074309270079","273577814075419466154781616910945826301"],"threshold":0.9},"id":"CVE-2019-17539-def83151","target":{"file":"libavformat/hlsenc.c"},"source":"https://github.com/ffmpeg/ffmpeg/commit/4521700f295f35da4768f88b570e0836a858ce7b","signature_version":"v1","deprecated":false}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}