Denial of Service Vulnerability in FFmpeg HLS Playlist Parsing
CVE-2023-6603
7.5HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 31 December 2024
Summary
A vulnerability exists within FFmpeg's HLS playlist parsing mechanism that allows a specially crafted HLS playlist to cause a denial of service. This occurs through a null pointer dereference during the initialization process, which can be exploited by malicious users to disrupt the functionality of applications utilizing this feature. Users are recommended to apply the latest security patches to mitigate this issue, ensuring continued protection against potential exploitation.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved