PT-2023-30463 · FFmpeg+1 · Ffmpeg+1

Dong Soo Kim

·

Published

2023-11-16

·

Updated

2026-02-06

·

CVE-2023-47470

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ffmpeg versions before github commit 4565747056a11356210ed8edcecb920105e40b60
Description The issue allows a remote attacker to achieve an out-of-array write, execute arbitrary code, and cause a denial of service (DoS) via the ref pic list struct function in libavcodec/evc ps.c.
Recommendations For versions before github commit 4565747056a11356210ed8edcecb920105e40b60, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the ref pic list struct function in libavcodec/evc ps.c until a patch is available.

Fix

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2023-8369
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2023-47470

Affected Products

Alt Linux
Ffmpeg