CVE-2024-36617

FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*

History

03 Jun 2025, 18:06

Type Values Removed Values Added
CPE cpe:2.3:a:ffmpeg:ffmpeg:6.1.1:*:*:*:*:*:*:* cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*

03 Jun 2025, 16:05

Type Values Removed Values Added
CPE cpe:2.3:a:ffmpeg:ffmpeg:6.1.1:*:*:*:*:*:*:*
First Time Ffmpeg ffmpeg
Ffmpeg
References () https://gist.github.com/1047524396/f20749f8addc8f86de9cfacf17ba29df - () https://gist.github.com/1047524396/f20749f8addc8f86de9cfacf17ba29df - Third Party Advisory
References () https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/cafdec.c#L274 - () https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/cafdec.c#L274 - Product
References () https://github.com/ffmpeg/ffmpeg/commit/d973fcbcc2f944752ff10e6a76b0b2d9329937a7 - () https://github.com/ffmpeg/ffmpeg/commit/d973fcbcc2f944752ff10e6a76b0b2d9329937a7 - Patch

02 Dec 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-29 18:15

Updated : 2025-06-03 18:06


NVD link : CVE-2024-36617

Mitre link : CVE-2024-36617

CVE.ORG link : CVE-2024-36617


JSON object : View

Products Affected

ffmpeg

  • ffmpeg
CWE
CWE-190

Integer Overflow or Wraparound