Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jx3-fx5f-r2c6

Опубликовано: 28 июл. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

FFmpeg discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.

Withdrawn

This advisory has been withdrawn because it has been found to be disputed. Please see the issue here for more information.

Original Despcription

FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.. This vulnerability is exploited via passing an unchecked argument.

Пакеты

Наименование

net.bramp.ffmpeg:ffmpeg

maven
Затронутые версииВерсия исправления

<= 0.7.0

Отсутствует

EPSS

Процентиль: 27%
0.00096
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no realistic use cases in which FFmpeg.java uses untrusted input for the path of the executable file.

EPSS

Процентиль: 27%
0.00096
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94