PT-2024-6072 · FFmpeg+4 · Ffmpeg+4
Published
2024-01-04
·
Updated
2025-11-21
·
CVE-2024-31582
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FFmpeg version n6.1
Description
The issue is related to a heap buffer overflow vulnerability in the
draw block rectangle function of libavfilter/vf codecview.c. This allows attackers to cause undefined behavior or a Denial of Service (DoS) via crafted input. The vulnerability may also enable attackers to access confidential data, compromise its integrity, and cause a service disruption using specially crafted input.Recommendations
For FFmpeg version n6.1, consider disabling the
draw block rectangle function in libavfilter/vf codecview.c as a temporary workaround until a patch is available. Restrict access to the libavfilter/vf codecview.c module to minimize the risk of exploitation. Avoid using crafted input that may trigger the heap buffer overflow vulnerability until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Ffmpeg
Linuxmint
Ubuntu