CVE-2024-36613

FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ffmpeg:ffmpeg:6.1.1:*:*:*:*:*:*:*

History

03 Jun 2025, 16:02

Type Values Removed Values Added
CPE cpe:2.3:a:ffmpeg:ffmpeg:6.1.1:*:*:*:*:*:*:*
Summary
  • (es) FFmpeg n6.1.1 tiene una vulnerabilidad en el demuxer DXA de la librería libavformat que permite un desbordamiento de enteros, lo que potencialmente puede resultar en una condición de denegación de servicio (DoS) u otro comportamiento indefinido.
References () https://gist.github.com/1047524396/0f4d90ef87553f772f888223085ac806 - () https://gist.github.com/1047524396/0f4d90ef87553f772f888223085ac806 - Third Party Advisory
References () https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/dxa.c#L125 - () https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/dxa.c#L125 - Product
References () https://github.com/ffmpeg/ffmpeg/commit/50d8e4f27398fd5778485a827d7a2817921f8540 - () https://github.com/ffmpeg/ffmpeg/commit/50d8e4f27398fd5778485a827d7a2817921f8540 - Patch
First Time Ffmpeg
Ffmpeg ffmpeg

03 Jan 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.2
CWE CWE-190

03 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-03 18:15

Updated : 2025-06-03 16:02


NVD link : CVE-2024-36613

Mitre link : CVE-2024-36613

CVE.ORG link : CVE-2024-36613


JSON object : View

Products Affected

ffmpeg

  • ffmpeg
CWE
CWE-190

Integer Overflow or Wraparound