PT-2024-4516 · FFmpeg+2 · Ffmpeg+2

Song Jiaxuan

+1

·

Published

2024-04-19

·

Updated

2025-07-23

·

CVE-2023-49501

CVSS v3.1

8.0

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Ffmpeg versions v.n6.1-3-g466799d4f5
Description: The issue is related to a buffer overflow vulnerability in the config eq output function, located in the libavfilter/asrc afirsrc.c component. This vulnerability allows a local attacker to execute arbitrary code. The exploitation of this issue can enable an attacker to run arbitrary code, potentially leading to system compromise.
Recommendations: For Ffmpeg version v.n6.1-3-g466799d4f5, consider disabling the config eq output function in the libavfilter/asrc afirsrc.c component as a temporary workaround until a patch is available. Restrict access to the vulnerable component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-05020
CVE-2023-49501
OESA-2024-2203
OPENSUSE-SU-2024:13895-1
USN-6803-1

Affected Products

Ffmpeg
Linuxmint
Ubuntu