CVE-2024-32228Classic Buffer Overflow in Ffmpeg

Severity
6.6MEDIUMNVD
EPSS
0.4%
top 41.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 1

Description

FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:HExploitability: 1.8 | Impact: 4.7

Affected Packages3 packages

debiandebian/ffmpeg< ffmpeg 7:7.0.1-3 (forky)
Debianffmpeg/ffmpeg< 7:7.0.1-3+1
NVDffmpeg/ffmpeg7.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4fr2-p4v7-6hwq: FFmpeg 72024-07-01
OSV
CVE-2024-32228: FFmpeg 72024-07-01

📋Vendor Advisories

1
Debian
CVE-2024-32228: ffmpeg - FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcd...2024