PT-2026-64412 · FFmpeg · Ffmpeg
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit filter 0 option. Attackers can provide a malicious video input where vf hqdn3d.config input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise spatial() to write beyond the allocation boundary, resulting in heap memory corruption.
Correção
Heap Based Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ffmpeg