Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-74ff-r9q5-73vp

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to be exploitable via specially crafted RM file has to be provided as input. This vulnerability appears to have been fixed in a7e032a277452366771951e29fd0bf2bd5c029f0 and later.

FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to be exploitable via specially crafted RM file has to be provided as input. This vulnerability appears to have been fixed in a7e032a277452366771951e29fd0bf2bd5c029f0 and later.

EPSS

Процентиль: 57%
0.00346
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to be exploitable via specially crafted RM file has to be provided as input. This vulnerability appears to have been fixed in a7e032a277452366771951e29fd0bf2bd5c029f0 and later.

CVSS3: 6.5
nvd
больше 7 лет назад

FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to be exploitable via specially crafted RM file has to be provided as input. This vulnerability appears to have been fixed in a7e032a277452366771951e29fd0bf2bd5c029f0 and later.

CVSS3: 6.5
debian
больше 7 лет назад

FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains ...

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость мультимедийной библиотеки FFmpeg, связанная с использованием памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальным данным

suse-cvrf
больше 7 лет назад

Security update for ffmpeg

EPSS

Процентиль: 57%
0.00346
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-416