PT-2024-4528 · FFmpeg+5 · Ffmpeg+5

Song Jiaxuan

+1

·

Published

2024-04-19

·

Updated

2025-08-25

·

CVE-2023-49502

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Ffmpeg version v.n6.1-3-g466799d4f5
Description: The issue is related to a buffer overflow in the ff bwdif filter intra c function, located in the libavfilter/bwdifdsp.c component. This allows an attacker to execute arbitrary code. The vulnerability is associated with uncontrolled copying of user data, which can be exploited by a remote attacker to achieve code execution.
Recommendations: For Ffmpeg version v.n6.1-3-g466799d4f5, consider disabling the ff bwdif filter intra c function as a temporary workaround until a patch is available. Restrict access to the libavfilter/bwdifdsp.c component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-05032
CVE-2023-49502
DLA-3928-1
DSA-5985-1
MGASA-2025-0067
OESA-2024-1805
OPENSUSE-SU-2024:13895-1
OPENSUSE-SU-2024:13906-1
OPENSUSE-SU-2024:13908-1
OPENSUSE-SU-2024_1468-1
OPENSUSE-SU-2024_1470-1
OPENSUSE-SU-2025_0862-1
OPENSUSE-SU-2026:20710-1
SUSE-SU-2024:1468-1
SUSE-SU-2024:1470-1
SUSE-SU-2024_1470-1
SUSE-SU-2025:0862-1
USN-6803-1

Affected Products

Astra Linux
Debian
Ffmpeg
Linuxmint
Suse
Ubuntu