Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-63757

Опубликовано: 18 дек. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.

A flaw was found in FFmpeg, an open-source multimedia framework. This vulnerability is an integer overflow within the yuv2ya16_X_c_template function. A remote attacker could exploit this by providing a specially crafted input, leading to a denial of service (DoS), which means the affected system or application would become unavailable.

Отчет

This vulnerability is rated Important for Red Hat products. An integer overflow in FFmpeg's yuv2ya16_X_c_template function can be exploited by a remote attacker providing specially crafted input, leading to a denial of service. This impacts components like ffmpeg, qt5-qtwebengine, and qt6-qtwebengine in Red Hat Community Projects and Red Hat Enterprise Linux AI.

Меры по смягчению последствий

To mitigate this issue, users should avoid processing untrusted or specially crafted media files with applications that utilize FFmpeg. Limiting the exposure of applications using FFmpeg to untrusted input can reduce the risk of a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3ffmpegOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2423583ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service

EPSS

Процентиль: 20%
0.00065
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.

CVSS3: 7.5
nvd
3 месяца назад

Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.

CVSS3: 7.5
debian
3 месяца назад

Integer overflow vulnerability in the yuv2ya16_X_c_template function i ...

suse-cvrf
2 месяца назад

Security update for ffmpeg-4

CVSS3: 7.5
github
3 месяца назад

Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.

EPSS

Процентиль: 20%
0.00065
Низкий

7.5 High

CVSS3