PatchSiren cyber security CVE debrief
CVE-2016-10192 Ffmpeg CVE debrief
CVE-2016-10192 is a critical FFmpeg vulnerability in ffserver.c where failure to validate chunk size can trigger a heap-based buffer overflow. The NVD record rates it 9.8/CRITICAL with network attack vector, low complexity, no privileges required, and no user interaction, making it a plausible remote code execution issue for exposed deployments.
- Vendor
- Ffmpeg
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-09
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-09
- Advisory updated
- 2026-05-13
Who should care
Anyone running FFmpeg deployments that include or expose the FFserver code path, especially legacy servers, downstream packages, and products that embed FFmpeg components. Security teams should also check for vendor backports and statically linked copies in appliances or applications.
Technical summary
The vulnerability is a heap-based buffer overflow in ffserver.c caused by failing to check chunk size. NVD maps it to CWE-119 and assigns CVSS 3.0 vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a remotely reachable flaw that can affect confidentiality, integrity, and availability. The affected version ranges listed in the record are FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2.
Defensive priority
Immediate
Recommended defensive actions
- Upgrade FFmpeg to a fixed release: 2.8.10 or later, 3.0.5 or later, 3.1.6 or later, or 3.2.2 or later, depending on the major line in use.
- If FFserver is not needed, disable or remove it to eliminate exposure of the vulnerable code path.
- Check downstream vendor packages and backports to confirm the fix is actually included in your build.
- Inventory embedded, statically linked, and appliance copies of FFmpeg that may not be covered by standard package updates.
- Restrict network exposure of any FFserver deployment while remediation is in progress.
- Use the FFmpeg security advisory and linked patch references to validate the remedied build version or commit lineage.
Evidence notes
The debrief is based on the supplied CVE description and the official NVD record. The NVD metadata lists CWE-119 and CVSS 3.0 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and its reference set includes the FFmpeg security page, two oss-security mailing list threads, and a GitHub patch commit. Version ranges are taken from the provided CVE data.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-10192 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-10192
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-10192 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10192
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://ffmpeg.org/security.html
[email protected] - Release Notes, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/FFmpeg/FFmpeg/commit/a5d25faa3f4b18dac737fdb35d0dd68eb0dc2156
[email protected] - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.