Integer Overflow Vulnerability in FFmpeg by FFmpeg Project
CVE-2024-22861

7.5HIGH

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
27 January 2024

What is CVE-2024-22861?

An integer overflow vulnerability has been identified in FFmpeg versions before n6.1, which can be exploited through the avcodec/osq module. This flaw allows attackers to send specially crafted inputs, leading to unexpected behavior and potential denial of service outcomes. Addressing this vulnerability is crucial as it could disrupt application availability and compromise system integrity. Users and administrators are advised to update to secure versions to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.