FFmpeg before commit a7e032a277452366771951e29fd0bf2bd5c029f0 contains a use-after-free vulnerability in the realmedia demuxer that can result in vulnerability allows attacker to read heap memory. This attack appear to be exploitable via specially crafted RM file has to be provided as input. This vulnerability appears to have been fixed in a7e032a277452366771951e29fd0bf2bd5c029f0 and later.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ffmpeg4Upgrade ffmpeg | Aug 22, 2024 | Jul 23, 2018 |
| Debian | — | Upgrade ffmpeg | Feb 25, 2019 | Jul 23, 2018 |
| Ffmpeg | — | Upgrade to FFmpeg version 4.0.2 | Sep 24, 2018 | Jul 23, 2018 |
| Suse | — | Upgrade libswscale-develUpgrade libavdevice57Upgrade libavformat-develUpgrade ffmpegUpgrade libavcodec57Upgrade libswscale4Upgrade libavutil55Upgrade libavresample3Upgrade libavformat57Upgrade libavresample-develUpgrade libswresample2Upgrade libavfilter6Upgrade libpostproc-develUpgrade libavcodec-develUpgrade libswresample-develUpgrade libavutil-develUpgrade libpostproc54 | Feb 4, 2022 | Jul 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub