CVE-2024-36613

FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ffmpeg:ffmpeg:6.1.1:*:*:*:*:*:*:*

History

03 Jun 2025, 16:02

Type Values Removed Values Added
First Time Ffmpeg ffmpeg
Ffmpeg
Summary
  • (es) FFmpeg n6.1.1 tiene una vulnerabilidad en el demuxer DXA de la librería libavformat que permite un desbordamiento de enteros, lo que potencialmente puede resultar en una condición de denegación de servicio (DoS) u otro comportamiento indefinido.
CPE cpe:2.3:a:ffmpeg:ffmpeg:6.1.1:*:*:*:*:*:*:*
References () https://gist.github.com/1047524396/0f4d90ef87553f772f888223085ac806 - () https://gist.github.com/1047524396/0f4d90ef87553f772f888223085ac806 - Third Party Advisory
References () https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/dxa.c#L125 - () https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/dxa.c#L125 - Product
References () https://github.com/ffmpeg/ffmpeg/commit/50d8e4f27398fd5778485a827d7a2817921f8540 - () https://github.com/ffmpeg/ffmpeg/commit/50d8e4f27398fd5778485a827d7a2817921f8540 - Patch

03 Jan 2025, 21:15

Type Values Removed Values Added
CWE CWE-190
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.2

03 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-03 18:15

Updated : 2025-06-03 16:02


NVD link : CVE-2024-36613

Mitre link : CVE-2024-36613

CVE.ORG link : CVE-2024-36613


JSON object : View

Products Affected

ffmpeg

  • ffmpeg
CWE
CWE-190

Integer Overflow or Wraparound