FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to be exploitable via specially crafted RM file has to be provided as input. This vulnerability appears to have been fixed in a7e032a277452366771951e29fd0bf2bd5c029f0 and later.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ffmpeg4Upgrade ffmpeg | Aug 22, 2024 | Jul 23, 2018 |
| Debian | — | Upgrade ffmpeg | Feb 25, 2019 | Jul 23, 2018 |
| Ffmpeg | — | Upgrade to FFmpeg version 4.0.2 | Sep 24, 2018 | Jul 23, 2018 |
| Suse | — | Upgrade libswresample-develUpgrade libavcodec-develUpgrade libpostproc-develUpgrade libavutil-develUpgrade libpostproc54Upgrade libavfilter6Upgrade libavformat-develUpgrade libavdevice57Upgrade libavformat57Upgrade libavcodec57Upgrade ffmpegUpgrade libswscale4Upgrade libavutil55Upgrade libavresample3Upgrade libswscale-develUpgrade libavresample-develUpgrade libswresample2 | Feb 4, 2022 | Jul 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub