CVE-2024-36617
published 2024-11-29CVE-2024-36617: FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
PriorityP422medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.24%
15.2th percentile
FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:5.1.5-0+deb12u1 (bookworm) | ffmpeg 7:5.1.5-0+deb12u1 (bookworm) |
| ffmpeg | ffmpeg | < 3.4.14 | 3.4.14 |
| ffmpeg | ffmpeg | >= 0 < 7:4.3.7-0+deb11u1 | 7:4.3.7-0+deb11u1 |
| ffmpeg | ffmpeg | >= 0 < 7:5.1.5-0+deb12u1 | 7:5.1.5-0+deb12u1 |
| ffmpeg | ffmpeg | >= 0 < 7:7.0.1-3 | 7:7.0.1-3 |
| ffmpeg | ffmpeg | >= 0 < 7:7.0.1-3 | 7:7.0.1-3 |
| ffmpeg | ffmpeg | >= 4.0 < 4.2.9 | 4.2.9 |
| ffmpeg | ffmpeg | >= 4.3 < 4.3.7 | 4.3.7 |
| ffmpeg | ffmpeg | >= 4.4 < 4.4.5 | 4.4.5 |
| ffmpeg | ffmpeg | >= 5.0 < 6.1.2 | 6.1.2 |
| ubuntu | ffmpeg | — | — |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.2MEDIUM
vendor_debian6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
FFmpeg 6.1.1 CAF Decoder integer overflow (Nessus ID 239902 / WID-SEC-2024-3572)
vuldb·2026-06-22·CVSS 6.2
CVE-2024-36617 [MEDIUM] FFmpeg 6.1.1 CAF Decoder integer overflow (Nessus ID 239902 / WID-SEC-2024-3572)
A vulnerability labeled as critical has been found in FFmpeg 6.1.1. Affected is an unknown function of the component CAF Decoder. Executing a manipulation can lead to integer overflow.
This vulnerability is registered as CVE-2024-36617. It is possible to launch the attack remotely. No exploit is available.
A patch should be applied to remediate this issue.
OSV
CVE-2024-36617: FFmpeg n6
osv·2024-11-29·CVSS 6.2
CVE-2024-36617 [MEDIUM] CVE-2024-36617: FFmpeg n6
FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
GHSA
GHSA-44gv-75g5-gcm5: FFmpeg n6
ghsa_unreviewed·2024-11-29
CVE-2024-36617 [MEDIUM] CWE-190 GHSA-44gv-75g5-gcm5: FFmpeg n6
FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
Ubuntu
FFmpeg vulnerability
vendor_ubuntu·2026-05-28
CVE-2024-36617 FFmpeg vulnerability
Title: FFmpeg vulnerability
Summary: FFmpeg could be made to crash if it received specially crafted input.
It was discovered that the FFmpeg CAF decoder incorrectly handled certain
file size calculations. An attacker could possibly use this issue to cause
FFmpeg to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
FFmpeg vulnerability
vendor_ubuntu·2025-01-08
CVE-2024-36617 FFmpeg vulnerability
Title: FFmpeg vulnerability
Summary: FFmpeg could be made to crash if it received specially crafted input.
It was discovered that FFmpeg incorrectly handled certain input, which
could lead to an integer overflow. An attacker could possibly use this
issue to cause a denial of service by crashing the application.
Instructions: After a standard system update you need to restart FFmpeg to make
all the necessary changes.
Debian
CVE-2024-36617: ffmpeg - FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
vendor_debian·2024·CVSS 6.2
CVE-2024-36617 [MEDIUM] CVE-2024-36617: ffmpeg - FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
Scope: local
bookworm: resolved (fixed in 7:5.1.5-0+deb12u1)
bullseye: resolved (fixed in 7:4.3.7-0+deb11u1)
forky: resolved (fixed in 7:7.0.1-3)
sid: resolved (fixed in 7:7.0.1-3)
trixie: resolved (fixed in 7:7.0.1-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-29
Published