PT-2024-4522 · FFmpeg+4 · Ffmpeg+4

Zeng Yunxiang

·

Published

2024-04-19

·

Updated

2025-11-21

·

CVE-2023-50007

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Ffmpeg version v.n6.1-3-g466799d4f5
Description: The issue is related to a Buffer Overflow in the av samples set silence function, located in the libavutil/samplefmt.c component of the Ffmpeg library. This allows a local attacker to potentially execute arbitrary code. The vulnerability is associated with a buffer overflow operation that can lead to the disclosure of protected information.
Recommendations: For Ffmpeg version v.n6.1-3-g466799d4f5, consider disabling the av samples set silence function as a temporary workaround until a patch is available. Restrict access to the libavutil/samplefmt.c component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-05026
CVE-2023-50007
DSA-5985-1
MGASA-2025-0306
OPENSUSE-SU-2024:13908-1
OPENSUSE-SU-2024:13909-1
USN-6803-1

Affected Products

Astra Linux
Debian
Ffmpeg
Linuxmint
Ubuntu