cbcvebase.
CVE-2023-6604
published 2025-01-06

CVE-2023-6604: A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or…

PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.44%
35.9th percentile
A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianffmpeg< ffmpeg 7:5.1.7-0+deb12u1 (bookworm)ffmpeg 7:5.1.7-0+deb12u1 (bookworm)
ffmpegffmpeg>= 0 < 7:4.3.9-0+deb11u17:4.3.9-0+deb11u1
ffmpegffmpeg>= 0 < 7:5.1.7-0+deb12u17:5.1.7-0+deb12u1
ffmpegffmpeg>= 0 < 7:7.1.1-17:7.1.1-1
ffmpegffmpeg>= 0 < 7:7.1.1-17:7.1.1-1
ffmpegffmpeg2.0 – 6.0

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.