CVE-2024-36619
published 2024-11-29CVE-2024-36619: FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.65%
47.5th percentile
FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading to a denial-of-service (DoS) condition.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:7.1-3 (forky) | ffmpeg 7:7.1-3 (forky) |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:7.1-3 | 7:7.1-3 |
| ffmpeg | ffmpeg | >= 0 < 7:7.1-3 | 7:7.1-3 |
| ffmpeg | ffmpeg | >= 0 < 7:2.8.17-0ubuntu0.1+esm12 | 7:2.8.17-0ubuntu0.1+esm12 |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.11-0ubuntu0.1+esm10 | 7:3.4.11-0ubuntu0.1+esm10 |
| ffmpeg | ffmpeg | >= 0 < 7:4.2.7-0ubuntu0.1+esm10 | 7:4.2.7-0ubuntu0.1+esm10 |
| ffmpeg | ffmpeg | >= 0 < 7:4.4.2-0ubuntu0.22.04.1+esm9 | 7:4.4.2-0ubuntu0.22.04.1+esm9 |
| ffmpeg | ffmpeg | >= 0 < 7:6.1.1-3ubuntu5+esm5 | 7:6.1.1-3ubuntu5+esm5 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
FFmpeg 6.1.1 WAVARC Decoder denial of service (Nessus ID 239902 / WID-SEC-2024-3572)
vuldb·2026-06-22·CVSS 5.3
CVE-2024-36619 [MEDIUM] FFmpeg 6.1.1 WAVARC Decoder denial of service (Nessus ID 239902 / WID-SEC-2024-3572)
A vulnerability labeled as problematic has been found in FFmpeg 6.1.1. The impacted element is an unknown function of the component WAVARC Decoder. Such manipulation leads to denial of service.
This vulnerability is documented as CVE-2024-36619. The attack can be executed remotely. There is not any exploit available.
It is advisable to implement a patch to correct this issue.
OSV
ffmpeg vulnerabilities
osv·2025-10-15·CVSS 8.8
CVE-2024-35365 [HIGH] ffmpeg vulnerabilities
ffmpeg vulnerabilities
It was discovered that FFmpeg did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected
Ubuntu 24.04 LTS. (CVE-2024-35365)
It was discovered that FFmpeg did not correctly handle certain integer
calculations. An attacker could possibly use this issue to cause a denial
of service. (CVE-2024-35366)
It was discovered that FFmpeg may perform an out-of-bounds read under
certain circumstances. An attacker could possibly use this issue to cause
a denial of service. (CVE-2024-35367)
It was discovered that FFmpeg did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary cod
GHSA
GHSA-m3h6-48g4-34gf: FFmpeg n6
ghsa_unreviewed·2024-11-29
CVE-2024-36619 [MEDIUM] CWE-190 GHSA-m3h6-48g4-34gf: FFmpeg n6
FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading to a denial-of-service (DoS) condition.
OSV
CVE-2024-36619: FFmpeg n6
osv·2024-11-29·CVSS 5.3
CVE-2024-36619 [MEDIUM] CVE-2024-36619: FFmpeg n6
FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading to a denial-of-service (DoS) condition.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2025-10-15·CVSS 8.8
CVE-2024-35368 [HIGH] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: Several security issues were fixed in FFmpeg.
It was discovered that FFmpeg did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected
Ubuntu 24.04 LTS. (CVE-2024-35365)
It was discovered that FFmpeg did not correctly handle certain integer
calculations. An attacker could possibly use this issue to cause a denial
of service. (CVE-2024-35366)
It was discovered that FFmpeg may perform an out-of-bounds read under
certain circumstances. An attacker could possibly use this issue to cause
a denial of service. (CVE-2024-35367)
It was discovered that FFmpeg did not correctly handle certain memory
operations. An attacker could possibly use t
Debian
CVE-2024-36619: ffmpeg - FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec librar...
vendor_debian·2024·CVSS 5.3
CVE-2024-36619 [MEDIUM] CVE-2024-36619: ffmpeg - FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec librar...
FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading to a denial-of-service (DoS) condition.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 7:7.1-3)
sid: resolved (fixed in 7:7.1-3)
trixie: resolved (fixed in 7:7.1-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-29
Published