PT-2025-7657 · FFmpeg+5 · Ffmpeg+5
0X20Z
·
Published
2025-01-14
·
Updated
2026-05-29
·
CVE-2025-1594
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions up to 7.1
Description
A critical vulnerability was found in FFmpeg, affecting the function
ff aac search for tns of the file libavcodec/aacenc tns.c of the component AAC Encoder. The manipulation leads to a stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.Recommendations
For FFmpeg versions up to 7.1, update to a version later than 7.1 to resolve the issue.
As a temporary workaround, consider disabling the
ff aac search for tns function until a patch is available.
Restrict access to the vulnerable AAC Encoder component to minimize the risk of exploitation.Exploit
Fix
DoS
Buffer Overflow
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Debian
Ffmpeg
Linuxmint
Red Os
Ubuntu