Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-36615

Опубликовано: 29 нояб. 2024
Источник: debian
EPSS Низкий

Описание

FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegfixed7:7.1-3package
ffmpegpostponedbookwormpackage

Примечания

  • https://github.com/ffmpeg/ffmpeg/commit/0ba058579f332b3060d8470a04ddd3fbf305be61 (n7.1)

  • Regression fix: https://github.com/FFmpeg/FFmpeg/commit/8c62d77139ca07390414fcfd26b2a4d506fed3b9 (n7.1)

EPSS

Процентиль: 22%
0.0007
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 1 года назад

FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.

CVSS3: 5.9
nvd
около 1 года назад

FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.

CVSS3: 5.9
github
около 1 года назад

FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.

EPSS

Процентиль: 22%
0.0007
Низкий