Null Pointer Dereference in FFmpeg Affects Media Processing
CVE-2022-3109
7.5HIGH
What is CVE-2022-3109?
A vulnerability in the FFmpeg package has been identified where the vp3_decode_frame
function within libavcodec/vp3.c
fails to check the return value of av_malloc()
. This oversight could lead to a null pointer dereference, potentially impacting the availability of applications relying on FFmpeg for media processing. It is crucial for users and administrators to apply available security patches to mitigate this risk.
Affected Version(s)
FFmpeg FFmpeg 5.1