aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 does not check for sscanf failure and consequently allows use of uninitialized variables.
Source: NIST
CVE-2019-12730 (ffmpeg)
Security in mind
aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 does not check for sscanf failure and consequently allows use of uninitialized variables.
Source: NIST
CVE-2019-12730 (ffmpeg)