CVE-2023-6604

A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=2334337 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*

History

05 Aug 2025, 18:05

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=2334337 - () https://bugzilla.redhat.com/show_bug.cgi?id=2334337 - Exploit, Issue Tracking, Third Party Advisory
CPE cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
Summary
  • (es) Se encontró un fallo en FFmpeg. Esta vulnerabilidad permite una carga de CPU adicional inesperada y un consumo de almacenamiento adicional, lo que puede provocar una degradación del rendimiento o la denegación del servicio mediante la demultiplexación de datos arbitrarios como datos con formato XBIN sin una validación de formato adecuada.
First Time Ffmpeg ffmpeg
Ffmpeg

06 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-06 17:15

Updated : 2025-08-05 18:05


NVD link : CVE-2023-6604

Mitre link : CVE-2023-6604

CVE.ORG link : CVE-2023-6604


JSON object : View

Products Affected

ffmpeg

  • ffmpeg
CWE
CWE-99

Improper Control of Resource Identifiers ('Resource Injection')

CWE-94

Improper Control of Generation of Code ('Code Injection')