PT-2024-6072 · FFmpeg+4 · Ffmpeg+4

Published

2024-01-04

·

Updated

2025-11-21

·

CVE-2024-31582

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg version n6.1
Description The issue is related to a heap buffer overflow vulnerability in the draw block rectangle function of libavfilter/vf codecview.c. This allows attackers to cause undefined behavior or a Denial of Service (DoS) via crafted input. The vulnerability may also enable attackers to access confidential data, compromise its integrity, and cause a service disruption using specially crafted input.
Recommendations For FFmpeg version n6.1, consider disabling the draw block rectangle function in libavfilter/vf codecview.c as a temporary workaround until a patch is available. Restrict access to the libavfilter/vf codecview.c module to minimize the risk of exploitation. Avoid using crafted input that may trigger the heap buffer overflow vulnerability until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-06896
CVE-2024-31582
DSA-5985-1
MGASA-2025-0306
OPENSUSE-SU-2024:13888-1
OPENSUSE-SU-2024:13895-1
USN-6803-1

Affected Products

Astra Linux
Debian
Ffmpeg
Linuxmint
Ubuntu