Denial of Service Vulnerability in FFmpeg HLS Playlist Parsing
CVE-2023-6603

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
31 December 2024

Summary

A vulnerability exists within FFmpeg's HLS playlist parsing mechanism that allows a specially crafted HLS playlist to cause a denial of service. This occurs through a null pointer dereference during the initialization process, which can be exploited by malicious users to disrupt the functionality of applications utilizing this feature. Users are recommended to apply the latest security patches to mitigate this issue, ensuring continued protection against potential exploitation.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.