CVE-2023-50008Classic Buffer Overflow in Ffmpeg

Severity
7.8HIGHNVD
EPSS
0.0%
top 91.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 19
Latest updateMay 30

Description

FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9 component.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDffmpeg/ffmpeg6.17.0
Debianffmpeg/ffmpeg< 7:5.1.7-0+deb12u1+2

Also affects: Fedora 38, 39, 40

Patches

🔴Vulnerability Details

3
OSV
CVE-2023-50008: FFmpeg v2024-04-19
GHSA
GHSA-6cjw-2w3q-pv7g: Buffer Overflow vulnerability in Ffmpeg v2024-04-19
CVEList
CVE-2023-50008: FFmpeg v2024-04-19

📋Vendor Advisories

2
Ubuntu
FFmpeg vulnerabilities2024-05-30
Debian
CVE-2023-50008: ffmpeg - FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrec...2023
CVE-2023-50008 — Classic Buffer Overflow in Ffmpeg | cvebase