rpm package
opensuse/ffmpeg-7&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Tumbleweed
Vulnerabilities (69)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-0518 | Med | 5.3 | < 7.1-3.1 | 7.1-3.1 | Jan 16, 2025 | Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C . This issue affects FFmpeg: 7.1. Issu | |
| CVE-2023-6601 | Med | 4.7 | < 7.1.3-1.1 | 7.1.3-1.1 | Jan 6, 2025 | A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions. | |
| CVE-2024-36613 | Med | 6.2 | < 7.1-3.1 | 7.1-3.1 | Jan 3, 2025 | FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior. | |
| CVE-2024-35365 | Hig | 8.8 | < 7.1-3.1 | 7.1-3.1 | Jan 3, 2025 | FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function. | |
| CVE-2023-6602 | Med | 5.3 | < 7.1.5-2.1 | 7.1.5-2.1 | Dec 31, 2024 | A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists. | |
| CVE-2024-35368 | Cri | 9.8 | < 7.1-4.1 | 7.1-4.1 | Nov 29, 2024 | FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c. | |
| CVE-2024-35367 | Cri | 9.1 | < 7.1.5-2.1 | 7.1.5-2.1 | Nov 29, 2024 | FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer | |
| CVE-2024-35366 | Cri | 9.1 | < 7.1.4-2.1 | 7.1.4-2.1 | Nov 29, 2024 | FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without | |
| CVE-2024-36616 | Med | 6.5 | < 7.1.1-4.1 | 7.1.1-4.1 | Nov 29, 2024 | An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file. | |
| CVE-2024-36615 | Med | 5.9 | < 7.1.1-4.1 | 7.1.1-4.1 | Nov 29, 2024 | FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread. | |
| CVE-2024-36618 | Med | 6.2 | < 7.1.1-4.1 | 7.1.1-4.1 | Nov 29, 2024 | FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) condition. | |
| CVE-2024-36617 | Med | 6.2 | < 7.1.1-4.1 | 7.1.1-4.1 | Nov 29, 2024 | FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder. | |
| CVE-2024-36619 | Med | 5.3 | < 7.1.1-4.1 | 7.1.1-4.1 | Nov 29, 2024 | FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading to a denial-of-service (DoS) condition. | |
| CVE-2024-7055 | Med | 6.3 | < 7.1-1.1 | 7.1-1.1 | Aug 6, 2024 | A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit h | |
| CVE-2024-32230 | Hig | 7.8 | < 7.0-2.1 | 7.0-2.1 | Jul 1, 2024 | FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0 | |
| CVE-2024-32229 | Hig | 8.4 | < 7.0-3.1 | 7.0-3.1 | Jul 1, 2024 | FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column. | |
| CVE-2024-32228 | Med | 6.6 | < 7.0-2.1 | 7.0-2.1 | Jul 1, 2024 | FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end. | |
| CVE-2023-48368 | Med | 5.9 | < 7.1.1-1.1 | 7.1.1-1.1 | May 16, 2024 | Improper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access. | |
| CVE-2023-47282 | Low | 3.9 | < 7.1.1-1.1 | 7.1.1-1.1 | May 16, 2024 | Out-of-bounds write in Intel(R) Media SDK all versions and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| CVE-2023-47169 | Low | 3.3 | < 7.1.1-1.1 | 7.1.1-1.1 | May 16, 2024 | Improper buffer restrictions in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access. |
- affected < 7.1-3.1fixed 7.1-3.1
Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C . This issue affects FFmpeg: 7.1. Issu
- affected < 7.1.3-1.1fixed 7.1.3-1.1
A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.
- affected < 7.1-3.1fixed 7.1-3.1
FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.
- affected < 7.1-3.1fixed 7.1-3.1
FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.
- affected < 7.1.5-2.1fixed 7.1.5-2.1
A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists.
- affected < 7.1-4.1fixed 7.1-4.1
FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.
- affected < 7.1.5-2.1fixed 7.1.5-2.1
FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer
- affected < 7.1.4-2.1fixed 7.1.4-2.1
FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without
- affected < 7.1.1-4.1fixed 7.1.1-4.1
An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file.
- affected < 7.1.1-4.1fixed 7.1.1-4.1
FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.
- affected < 7.1.1-4.1fixed 7.1.1-4.1
FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) condition.
- affected < 7.1.1-4.1fixed 7.1.1-4.1
FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
- affected < 7.1.1-4.1fixed 7.1.1-4.1
FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading to a denial-of-service (DoS) condition.
- affected < 7.1-1.1fixed 7.1-1.1
A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit h
- affected < 7.0-2.1fixed 7.0-2.1
FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0
- affected < 7.0-3.1fixed 7.0-3.1
FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.
- affected < 7.0-2.1fixed 7.0-2.1
FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.
- affected < 7.1.1-1.1fixed 7.1.1-1.1
Improper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.
- affected < 7.1.1-1.1fixed 7.1.1-1.1
Out-of-bounds write in Intel(R) Media SDK all versions and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access.
- affected < 7.1.1-1.1fixed 7.1.1-1.1
Improper buffer restrictions in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.
Page 3 of 4