Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
07 Jan 2026, 17:32
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Fedoraproject fedora
Ffmpeg ffmpeg Ffmpeg Fedoraproject |
|
| References | () https://ffmpeg.org/ - Product | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/ - Mailing List | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/ - Mailing List | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/ - Mailing List | |
| References | () https://trac.ffmpeg.org/ticket/10738 - Issue Tracking | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/ - Mailing List | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/ - Mailing List | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/ - Mailing List | |
| CPE | cpe:2.3:a:ffmpeg:ffmpeg:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:ffmpeg:ffmpeg:8.1:dev:*:*:*:*:*:* cpe:2.3:a:ffmpeg:ffmpeg:7.1:dev:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* cpe:2.3:a:ffmpeg:ffmpeg:7.1.3:*:*:*:*:*:*:* cpe:2.3:a:ffmpeg:ffmpeg:7.1:*:*:*:*:*:*:* cpe:2.3:a:ffmpeg:ffmpeg:7.0:*:*:*:*:*:*:* cpe:2.3:a:ffmpeg:ffmpeg:7.0.1:*:*:*:*:*:*:* cpe:2.3:a:ffmpeg:ffmpeg:8.0:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:a:ffmpeg:ffmpeg:7.0.3:*:*:*:*:*:*:* cpe:2.3:a:ffmpeg:ffmpeg:7.1.2:*:*:*:*:*:*:* cpe:2.3:a:ffmpeg:ffmpeg:7.1.1:*:*:*:*:*:*:* cpe:2.3:a:ffmpeg:ffmpeg:7.2:dev:*:*:*:*:*:* cpe:2.3:a:ffmpeg:ffmpeg:8.0.1:*:*:*:*:*:*:* |
04 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 08:38
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://ffmpeg.org/ - | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/ - | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/ - | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/ - | |
| References | () https://trac.ffmpeg.org/ticket/10738 - |
25 Oct 2024, 20:35
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-125 |
03 Jul 2024, 01:43
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-121 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
10 Jun 2024, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary |
|
19 Apr 2024, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-04-19 17:15
Updated : 2026-01-07 17:32
NVD link : CVE-2023-51791
Mitre link : CVE-2023-51791
CVE.ORG link : CVE-2023-51791
JSON object : View
Products Affected
ffmpeg
- ffmpeg
fedoraproject
- fedora
CWE
CWE-125
Out-of-bounds Read
