Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q56j-8x89-gvgg

Опубликовано: 29 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).

libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).

EPSS

Процентиль: 49%
0.00254
Низкий

8.1 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 2 лет назад

libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).

CVSS3: 8.1
nvd
около 2 лет назад

libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).

CVSS3: 8.1
debian
около 2 лет назад

libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and ...

suse-cvrf
около 2 лет назад

Security update for ffmpeg

suse-cvrf
около 2 лет назад

This update has recommended fixes for ffmpeg-4

EPSS

Процентиль: 49%
0.00254
Низкий

8.1 High

CVSS3

Дефекты

CWE-416