CVE-2025-25471NULL Pointer Dereference in Ffmpeg

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 67.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 18
Latest updateFeb 19

Description

FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

debiandebian/ffmpeg

🔴Vulnerability Details

2
GHSA
GHSA-jv3p-xr22-v88x: FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov2025-02-19
OSV
CVE-2025-25471: FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov2025-02-18

📋Vendor Advisories

1
Debian
CVE-2025-25471: ffmpeg - FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer ...2025