PT-2024-10422 · FFmpeg+4 · Ffmpeg+4
Published
2024-02-12
·
Updated
2026-05-27
·
CVE-2024-35366
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FFmpeg version 6.1.1
Description
The issue is related to an integer overflow vulnerability in the parse options function of sbgdec.c within the libavformat module. This vulnerability allows for negative duration values to be accepted without proper bounds checking due to inadequate input validation when parsing certain options. It may enable a remote attacker to cause a denial of service by exploiting the buffer copy without input validation.
Recommendations
For FFmpeg version 6.1.1, consider disabling the
parse options function in the sbgdec.c component of the libavformat module as a temporary workaround until a patch is available. Restrict access to the libavformat module to minimize the risk of exploitation. Avoid using the affected module for parsing options that may lead to negative duration values until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Integer Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Ffmpeg
Linuxmint
Red Os
Ubuntu