CVE-2024-35369
published 2024-11-29CVE-2024-35369: In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of…
PriorityP421medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.24%
14.6th percentile
In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:7.0.1-3 (forky) | ffmpeg 7:7.0.1-3 (forky) |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:7.0.1-3 | 7:7.0.1-3 |
| ffmpeg | ffmpeg | >= 0 < 7:7.0.1-3 | 7:7.0.1-3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
FFmpeg 6.1.1 Speex Codec Extradata Parser avcodec/speexdec.c integer overflow (WID-SEC-2024-3572)
vuldb·2026-06-22·CVSS 5.5
CVE-2024-35369 [MEDIUM] FFmpeg 6.1.1 Speex Codec Extradata Parser avcodec/speexdec.c integer overflow (WID-SEC-2024-3572)
A vulnerability categorized as critical has been discovered in FFmpeg 6.1.1. This affects an unknown part of the file avcodec/speexdec.c of the component Speex Codec Extradata Parser. Executing a manipulation can lead to integer overflow.
This vulnerability is registered as CVE-2024-35369. It is possible to launch the attack remotely. No exploit is available.
It is advisable to implement a patch to correct this issue.
GHSA
GHSA-c655-qv2v-73rm: In FFmpeg version n6
ghsa_unreviewed·2024-11-29
CVE-2024-35369 [MEDIUM] CWE-190 GHSA-c655-qv2v-73rm: In FFmpeg version n6
In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process.
OSV
CVE-2024-35369: In FFmpeg version n6
osv·2024-11-29·CVSS 5.5
CVE-2024-35369 [MEDIUM] CVE-2024-35369: In FFmpeg version n6
In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process.
Debian
CVE-2024-35369: ffmpeg - In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a p...
vendor_debian·2024·CVSS 5.5
CVE-2024-35369 [MEDIUM] CVE-2024-35369: ffmpeg - In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a p...
In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 7:7.0.1-3)
sid: resolved (fixed in 7:7.0.1-3)
trixie: resolved (fixed in 7:7.0.1-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-29
Published