PT-2025-6903 · FFmpeg · Ffmpeg
0X20Z
·
Published
2025-02-08
·
Updated
2025-06-03
·
CVE-2025-1373
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
FFmpeg versions prior to 7.1
Description:
A problem has been found in the function
mov read trak of the file libavformat/mov.c of the component MOV Parser. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.Recommendations:
For FFmpeg versions prior to 7.1, apply a patch to fix this issue. As a temporary workaround, consider restricting access to the
mov read trak function of the MOV Parser component until a patch is available.Exploit
Fix
Improper Resource Release
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ffmpeg