Skip to content

Vulnerabilities reported in FFmpeg #293

@prasadayush

Description

@prasadayush

Vulnerabilities are reported in ffmpeg package

CVE-2023-49528 - Attack complexity: low, DoS - High, High severity, Remote execution --> Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.

CVE-2024-31578 - Attack complexity: low, Attack vector: network, High severity --> FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions