Performance Degradation in FFmpeg Due to Flaw in Data Demuxing
CVE-2023-6604

Currently unrated

Key Information:

Vendor

FFmpeg

Status
Vendor
CVE Published:
6 January 2025

What is CVE-2023-6604?

A vulnerability in FFmpeg allows the demuxing of arbitrary data formatted as XBIN without adequate format validation. This flaw leads to unexpected additional CPU load and excessive storage consumption. As a result, it can significantly degrade the performance of applications utilizing FFmpeg, potentially causing a denial of service.

References

Timeline

  • Vulnerability published

.