CVE-2023-6604
published 2025-01-06CVE-2023-6604: A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.44%
35.9th percentile
A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:5.1.7-0+deb12u1 (bookworm) | ffmpeg 7:5.1.7-0+deb12u1 (bookworm) |
| ffmpeg | ffmpeg | >= 0 < 7:4.3.9-0+deb11u1 | 7:4.3.9-0+deb11u1 |
| ffmpeg | ffmpeg | >= 0 < 7:5.1.7-0+deb12u1 | 7:5.1.7-0+deb12u1 |
| ffmpeg | ffmpeg | >= 0 < 7:7.1.1-1 | 7:7.1.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:7.1.1-1 | 7:7.1.1-1 |
| ffmpeg | ffmpeg | 2.0 – 6.0 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-6604: A flaw was found in FFmpeg
osv·2025-01-06·CVSS 5.3
CVE-2023-6604 [MEDIUM] CVE-2023-6604: A flaw was found in FFmpeg
A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.
GHSA
GHSA-j6rq-mppc-h3jr: A flaw was found in FFmpeg
ghsa_unreviewed·2025-01-06
CVE-2023-6604 [MEDIUM] CWE-94 GHSA-j6rq-mppc-h3jr: A flaw was found in FFmpeg
A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.
Debian
CVE-2023-6604: ffmpeg - A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU ...
vendor_debian·2023·CVSS 5.3
CVE-2023-6604 [MEDIUM] CVE-2023-6604: ffmpeg - A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU ...
A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.
Scope: local
bookworm: resolved (fixed in 7:5.1.7-0+deb12u1)
bullseye: resolved (fixed in 7:4.3.9-0+deb11u1)
forky: resolved (fixed in 7:7.1.1-1)
sid: resolved (fixed in 7:7.1.1-1)
trixie: resolved (fixed in 7:7.1.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-06
Published