CVE-2019-18214

The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurrent conversions because many FFmpeg processes may be running at once. (The workload is not queued for serial execution.)
References
Link Resource
https://github.com/PaulLereverend/NextcloudVideo_Converter/issues/22 Exploit Issue Tracking Third Party Advisory
https://github.com/PaulLereverend/NextcloudVideo_Converter/issues/22 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:video_converter_project:video_converter:0.1.0:*:*:*:*:nextcloud:*:*

History

21 Nov 2024, 04:32

Type Values Removed Values Added
References () https://github.com/PaulLereverend/NextcloudVideo_Converter/issues/22 - Exploit, Issue Tracking, Third Party Advisory () https://github.com/PaulLereverend/NextcloudVideo_Converter/issues/22 - Exploit, Issue Tracking, Third Party Advisory

Information

Published : 2019-10-19 14:15

Updated : 2024-11-21 04:32


NVD link : CVE-2019-18214

Mitre link : CVE-2019-18214

CVE.ORG link : CVE-2019-18214


JSON object : View

Products Affected

video_converter_project

  • video_converter
CWE
CWE-772

Missing Release of Resource after Effective Lifetime