Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-22920

Опубликовано: 18 фев. 2025
Источник: debian
EPSS Низкий

Описание

A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegnot-affectedpackage

Примечания

  • https://trac.ffmpeg.org/ticket/11389

  • Introduced with: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/545de54e3e0ce5ad1285aa5e111e6657ad803f79

  • Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/4bf784c0e5615c3f934e677d5de093a8be7da7ae

EPSS

Процентиль: 34%
0.00137
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
12 месяцев назад

A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).

CVSS3: 5.3
nvd
12 месяцев назад

A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).

CVSS3: 5.3
github
12 месяцев назад

A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).

EPSS

Процентиль: 34%
0.00137
Низкий