Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-48434

Опубликовано: 29 мар. 2023
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
Версия до 5.1.2 (исключая)

EPSS

Процентиль: 49%
0.00254
Низкий

8.1 High

CVSS3

Дефекты

CWE-416
CWE-416

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 2 лет назад

libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).

CVSS3: 8.1
debian
около 2 лет назад

libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and ...

suse-cvrf
около 2 лет назад

Security update for ffmpeg

suse-cvrf
около 2 лет назад

This update has recommended fixes for ffmpeg-4

CVSS3: 8.1
github
около 2 лет назад

libavcodec/pthread_frame.c in FFmpeg before 5.1.2, as used in VLC and other products, leaves stale hwaccel state in worker threads, which allows attackers to trigger a use-after-free and execute arbitrary code in some circumstances (e.g., hardware re-initialization upon a mid-video SPS change when Direct3D11 is used).

EPSS

Процентиль: 49%
0.00254
Низкий

8.1 High

CVSS3

Дефекты

CWE-416
CWE-416