CVE-2022-1475Integer Overflow or Wraparound in Ffmpeg

Severity
5.5MEDIUMNVD
OSV6.5
EPSS
0.1%
top 73.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateSep 18

Description

An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729_parse() in llibavcodec/g729_parser.c when processing a specially crafted file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDffmpeg/ffmpeg4.24.4.2+1
debiandebian/ffmpeg< ffmpeg 7:4.4.2-1 (bookworm)
Debianffmpeg/ffmpeg< 7:4.3.4-0+deb11u1+3
Ubuntuffmpeg/ffmpeg< 7:3.4.11-0ubuntu0.1+2
CVEListV5ffmpeg/ffmpegbefore 4.4.2, before 5.0.1+1

Patches

🔴Vulnerability Details

3
OSV
ffmpeg vulnerabilities2022-06-08
GHSA
GHSA-gcqf-mvg9-pf79: An integer overflow vulnerability was found in FFmpeg 52022-05-03
OSV
CVE-2022-1475: An integer overflow vulnerability was found in FFmpeg versions before 42022-05-02

📋Vendor Advisories

3
Red Hat
kernel: drm/amdgpu: SDMA update use unlocked iterator2025-09-18
Ubuntu
FFmpeg vulnerabilities2022-06-08
Debian
CVE-2022-1475: ffmpeg - An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and ...2022