CVE-2025-1594
published 2025-02-23CVE-2025-1594: A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file…
PriorityP357high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.53%
41.5th percentile
A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected
61 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:5.1.8-0+deb12u1 (bookworm) | ffmpeg 7:5.1.8-0+deb12u1 (bookworm) |
| ffmpeg | ffmpeg | <= 7.1 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FFmpeg vulnerability
vendor_ubuntu·2025-09-04
CVE-2025-1594 FFmpeg vulnerability
Title: FFmpeg vulnerability
Summary: FFmpeg could be made to crash if it received specially crafted input.
It was discovered that FFmpeg incorrectly handled the calculation of
LPC order, which could lead to a stack-based buffer overflow. An attacker
could possibly use this issue to cause FFmpeg to crash, resulting in a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2025-1594: ffmpeg - A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1...
vendor_debian·2025·CVSS 5.3
CVE-2025-1594 [MEDIUM] CVE-2025-1594: ffmpeg - A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1...
A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Scope: local
bookworm: resolved (fixed in 7:5.1.8-0+deb12u1)
bullseye: resolved (fixed in 7:4.3.9-0+deb11u2)
forky: resolved (fixed in 7:7.1.2-1)
sid: resolved (fixed in 7:7.1.2-1)
trixie: resolved (fixed in 7:7.1.2-0+deb13u1)
VulDB
FFmpeg up to 7.1 AAC Encoder libavcodec/aacenc_tns.c ff_aac_search_for_tns stack-based overflow (Nessus ID 265685 / WID-SEC-2025-0429)
vuldb·2026-06-22·CVSS 8.8
CVE-2025-1594 [HIGH] FFmpeg up to 7.1 AAC Encoder libavcodec/aacenc_tns.c ff_aac_search_for_tns stack-based overflow (Nessus ID 265685 / WID-SEC-2025-0429)
A vulnerability described as critical has been identified in FFmpeg up to 7.1. The affected element is the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. Such manipulation leads to stack-based buffer overflow.
This vulnerability is listed as CVE-2025-1594. The attack may be performed from remote. In addition, an exploit is available.
GHSA
GHSA-37pp-xmcw-vg4w: A vulnerability, which was classified as critical, was found in FFmpeg up to 7
ghsa_unreviewed·2025-02-23
CVE-2025-1594 [MEDIUM] CWE-119 GHSA-37pp-xmcw-vg4w: A vulnerability, which was classified as critical, was found in FFmpeg up to 7
A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
OSV
CVE-2025-1594: A vulnerability, which was classified as critical, was found in FFmpeg up to 7
osv·2025-02-23·CVSS 5.3
CVE-2025-1594 [MEDIUM] CVE-2025-1594: A vulnerability, which was classified as critical, was found in FFmpeg up to 7
A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
No detection rules found.
No public exploits indexed.
2025-02-23
Published