FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.
7:2.8.17-0ubuntu0.1+esm177:3.4.11-0ubuntu0.1+esm157:4.2.7-0ubuntu0.1+esm167:4.4.2-0ubuntu0.22.04.1+esm157:6.1.1-3ubuntu5+esm137:8.0.1-3ubuntu2+esm4Exploitability
AV:LAC:LAT:NPR:NUI:PVulnerable System
VC:HVI:HVA:HSubsequent System
SC:NSI:NSA:NCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N