CVE-2024-22862
published 2024-01-27CVE-2024-22862: Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser.
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.19%
64.5th percentile
Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:6.1-1 (forky) | ffmpeg 7:6.1-1 (forky) |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:6.1-1 | 7:6.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:6.1-1 | 7:6.1-1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-22862: Integer overflow vulnerability in FFmpeg before n6
osv·2024-01-27·CVSS 9.8
CVE-2024-22862 [CRITICAL] CVE-2024-22862: Integer overflow vulnerability in FFmpeg before n6
Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser.
GHSA
GHSA-44vq-656c-r27f: Integer overflow vulnerability in FFmpeg before n6
ghsa_unreviewed·2024-01-27
CVE-2024-22862 [CRITICAL] CWE-190 GHSA-44vq-656c-r27f: Integer overflow vulnerability in FFmpeg before n6
Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser.
Debian
CVE-2024-22862: ffmpeg - Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to...
vendor_debian·2024·CVSS 9.8
CVE-2024-22862 [CRITICAL] CVE-2024-22862: ffmpeg - Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to...
Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 7:6.1-1)
sid: resolved (fixed in 7:6.1-1)
trixie: resolved (fixed in 7:6.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-01-27
Published