PT-2024-4524 · FFmpeg+3 · Ffmpeg+3

Zeng Yunxiang

·

Published

2024-04-19

·

Updated

2025-06-06

·

CVE-2023-50009

CVSS v3.1

8.0

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions: FFmpeg versions prior to the fixed version
Description: The issue is related to a buffer overflow vulnerability in the ff gaussian blur 8 function, located in libavfilter/edge template.c, which can allow a local attacker to execute arbitrary code. This vulnerability is associated with a heap-based buffer overflow.
Recommendations: For FFmpeg versions prior to the fixed version, consider disabling the ff gaussian blur 8 function as a temporary workaround until a patch is available. Restrict access to the libavfilter/edge template.c component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-05028
CVE-2023-50009
OPENSUSE-SU-2024:13934-1
USN-6803-1

Affected Products

Astra Linux
Ffmpeg
Linuxmint
Ubuntu