Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-564v-jr2q-mgwf

Опубликовано: 19 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.2
CVSS3: 8.1

Описание

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.

EPSS

Процентиль: 18%
0.00261
Низкий

7.2 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 8.1
ubuntu
8 дней назад

(FFmpeg before commit 65b0dab contains an out-of-bounds read in the DAS ...)

CVSS3: 8.1
nvd
8 дней назад

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.

CVSS3: 8.1
debian
8 дней назад

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DAS ...

EPSS

Процентиль: 18%
0.00261
Низкий

7.2 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-125