Описание
An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729_parse() in llibavcodec/g729_parser.c when processing a specially crafted file.
Ссылки
- Issue TrackingPatchThird Party Advisory
- ExploitPatchVendor Advisory
- Issue TrackingPatchThird Party Advisory
- ExploitPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.2 (включая) до 4.4.2 (исключая)
Одно из
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:5.0:*:*:*:*:*:*:*
EPSS
Процентиль: 27%
0.00095
Низкий
5.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-190
CWE-190
Связанные уязвимости
CVSS3: 5.5
ubuntu
почти 4 года назад
An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729_parse() in llibavcodec/g729_parser.c when processing a specially crafted file.
CVSS3: 5.5
debian
почти 4 года назад
An integer overflow vulnerability was found in FFmpeg versions before ...
CVSS3: 5.5
github
почти 4 года назад
An integer overflow vulnerability was found in FFmpeg 5.0.1 and in previous versions in g729_parse() in llibavcodec/g729_parser.c when processing a specially crafted file.
EPSS
Процентиль: 27%
0.00095
Низкий
5.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-190
CWE-190