PT-2024-27097 · FFmpeg+3 · Ffmpeg+3

Published

2024-04-04

·

Updated

2025-10-15

·

CVE-2024-36619

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions FFmpeg version 6.1.1
Description The issue is related to an integer overflow in the WAVARC decoder of the libavcodec library when handling certain block types. This can lead to a denial-of-service (DoS) condition.
Recommendations For FFmpeg version 6.1.1, consider updating to a newer version that addresses the integer overflow issue in the WAVARC decoder of the libavcodec library to prevent potential denial-of-service (DoS) conditions.

Fix

DoS

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-12480
CVE-2024-36619
OESA-2025-1017
OPENSUSE-SU-2025:15177-1
USN-7823-1

Affected Products

Ffmpeg
Linuxmint
Ubuntu
Libavcodec