PT-2025-6903 · FFmpeg · Ffmpeg

0X20Z

·

Published

2025-02-08

·

Updated

2025-06-03

·

CVE-2025-1373

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: FFmpeg versions prior to 7.1
Description: A problem has been found in the function mov read trak of the file libavformat/mov.c of the component MOV Parser. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
Recommendations: For FFmpeg versions prior to 7.1, apply a patch to fix this issue. As a temporary workaround, consider restricting access to the mov read trak function of the MOV Parser component until a patch is available.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-06797
CVE-2025-1373

Affected Products

Ffmpeg