CVE-2022-2566
published 2022-09-23CVE-2022-2566: A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the…
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.66%
47.9th percentile
A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a small allocation with `av_calloc()`. An attacker can cause remote code execution via a malicious mp4 file. We recommend upgrading past commit c953baa084607dd1d84c3bfcce3cf6a87c3e6e05
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:5.1.1-1 (bookworm) | ffmpeg 7:5.1.1-1 (bookworm) |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:5.1.1-1 | 7:5.1.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:5.1.1-1 | 7:5.1.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:5.1.1-1 | 7:5.1.1-1 |
| ffmpeg | ffmpeg | >= 5.1 < unspecified | unspecified |
| ffmpeg | ffmpeg | >= ab77b878f1205225c6de1370fb0e998dbcc8bc69 < unspecified | unspecified |
| ffmpeg | ffmpeg | >= unspecified < c953baa084607dd1d84c3bfcce3cf6a87c3e6e05 | c953baa084607dd1d84c3bfcce3cf6a87c3e6e05 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m864-5788-g574: A heap out-of-bounds memory write exists in FFMPEG since version 5
ghsa_unreviewed·2022-09-25
CVE-2022-2566 [HIGH] CWE-122 GHSA-m864-5788-g574: A heap out-of-bounds memory write exists in FFMPEG since version 5
A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a small allocation with `av_calloc(). An attacker can cause remote code execution via a malicious mp4 file. We recommend upgrading past commit c953baa084607dd1d84c3bfcce3cf6a87c3e6e05
OSV
CVE-2022-2566: A heap out-of-bounds memory write exists in FFMPEG since version 5
osv·2022-09-23·CVSS 7.8
CVE-2022-2566 [HIGH] CVE-2022-2566: A heap out-of-bounds memory write exists in FFMPEG since version 5
A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a small allocation with `av_calloc()`. An attacker can cause remote code execution via a malicious mp4 file. We recommend upgrading past commit c953baa084607dd1d84c3bfcce3cf6a87c3e6e05
Debian
CVE-2022-2566: ffmpeg - A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size c...
vendor_debian·2022·CVSS 9.0
CVE-2022-2566 [CRITICAL] CVE-2022-2566: ffmpeg - A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size c...
A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a small allocation with `av_calloc()`. An attacker can cause remote code execution via a malicious mp4 file. We recommend upgrading past commit c953baa084607dd1d84c3bfcce3cf6a87c3e6e05
Scope: local
bookworm: resolved (fixed in 7:5.1.1-1)
bullseye: resolved
forky: resolved (fixed in 7:5.1.1-1)
sid: resolved (fixed in 7:5.1.1-1)
trixie: resolved (fixed in 7:5.1.1-1)
No detection rules found.
No public exploits indexed.
arXiv
Exploiting Cross-Layer Vulnerabilities: Off-Path Attacks on the TCP/IP Protocol Suite
arxiv_fulltext·2024-11-19
Exploiting Cross-Layer Vulnerabilities: Off-Path Attacks on the TCP/IP Protocol Suite
plain
Exploiting Cross-Layer Vulnerabilities: Off-Path Attacks on the TCP/IP Protocol Suite
Xuewei Feng*,
Qi Li* ,
Kun Sun ,
Ke Xu* ,
and Jianping Wu* ,
*Tsinghua University, Laboratory, Mason University
mailto:[email protected]@gmail.com, \qli01@, xuke@\tsinghua.edu.cn, [email protected], [email protected]
Ben Trovato
[email protected]
1234-5678-9012
G.K.M. Tobin
[1]
[email protected]
Institute for Clarity in Documentation
P.O. Box 1212
Dublin
Ohio
USA
43017-6221
Lars Th\"ald
The Th\"ald Group
1 Th\"ald Circle
Hekla
Iceland
[email protected]
Valerie B\'eranger
Inria Paris-Rocquencourt
Rocquencourt
France
Aparna Patel
Rajiv Gandhi University
Rono-Hills
Doimukh
Arunachal Pradesh
India
Huifen Chan
Tsinghua University
30 Shuangqing Rd
Haidian Qu
Be
Bugzilla
CVE-2022-44730 batik: Server-Side Request Forgery vulnerability
bugzilla·2023-08-23·CVSS 4.4
CVE-2022-44730 [MEDIUM] CVE-2022-44730 batik: Server-Side Request Forgery vulnerability
CVE-2022-44730 batik: Server-Side Request Forgery vulnerability
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.
A malicious SVG can probe user profile / data and send it directly as parameter to a URL.
References:
https://lists.apache.org/thread/58m5817jr059f4v1zogh0fngj9pwjyj0
https://xmlgraphics.apache.org/security.html
http://www.openwall.com/lists/oss-security/2023/08/22/3
http://www.openwall.com/lists/oss-security/2023/08/22/5
Discussion:
Versions Affected: Batik 1.0 - 1.16
References:
https://issues.apache.org/jira/browse/BATIK-1347
https://github.com/advisories/GHSA-2474-2566-3qxp
https://github.com/apache/xmlgraphics-batik/commit/f9ae69233eadfbd392a4a08a55618f97343b467
2022-09-23
Published