CVE-2023-6604Resource Injection in Ffmpeg

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 72.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 6

Description

A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

debiandebian/ffmpeg< ffmpeg 7:5.1.7-0+deb12u1 (bookworm)
Debianffmpeg/ffmpeg< 7:4.3.9-0+deb11u1+3
NVDffmpeg/ffmpeg2.06.0

🔴Vulnerability Details

2
OSV
CVE-2023-6604: A flaw was found in FFmpeg2025-01-06
GHSA
GHSA-j6rq-mppc-h3jr: A flaw was found in FFmpeg2025-01-06

📋Vendor Advisories

1
Debian
CVE-2023-6604: ffmpeg - A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU ...2023