PT-2024-8679 · FFmpeg+1 · Ffmpeg+1

Zeng Yunxiang

·

Published

2024-07-01

·

Updated

2025-11-26

·

CVE-2024-32228

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg version 7.0
Description The issue is related to a buffer overflow in the hevc frame end function of the FFmpeg library, located in libavcodec/hevcdec.c. This can lead to an out-of-bounds operation in memory, potentially allowing an attacker to disclose protected information. The vulnerability is associated with a SEGV at libavcodec/hevcdec.c:2947:22 in the hevc frame end function.
Recommendations For FFmpeg version 7.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-10281
CVE-2024-32228
OESA-2024-1936
OPENSUSE-SU-2024:14097-1
OPENSUSE-SU-2024:14221-1
OPENSUSE-SU-2024:14226-1

Affected Products

Debian
Ffmpeg