A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.2 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-273651.
CVSS Details
- CVSS 4.0 Base Score: 6.9 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 6.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ffmpeg | Dec 5, 2025 | Aug 6, 2024 |
| Debian | — | Upgrade ffmpeg | Aug 15, 2024 | Aug 6, 2024 |
| Ffmpeg | — | Upgrade to FFmpeg version 6.1.2Upgrade to FFmpeg version 4.3.8Upgrade to FFmpeg version 7.0.2Upgrade to FFmpeg version 4.4.5Upgrade to FFmpeg version 7.1Upgrade to FFmpeg version 5.1.6 | Aug 6, 2024 | Aug 6, 2024 |
| Suse | — | Upgrade libavresample4_0Upgrade libswresample3_9Upgrade ffmpeg-4-libavcodec-develUpgrade ffmpeg-4-private-develUpgrade libavcodec61Upgrade ffmpeg-4-libavutil-develUpgrade libavcodec58_134-32bitUpgrade libavfilter7_110-32bitUpgrade libpostproc58Upgrade ffmpeg-4-libavdevice-develUpgrade libavutil56_70-32bitUpgrade ffmpeg-4-libpostproc-develUpgrade libswscale8Upgrade ffmpeg-4Upgrade libavutil59Upgrade libswscale5_9-32bitUpgrade libavdevice58_13Upgrade libavfilter10Upgrade libswresample5Upgrade libavdevice58_13-32bitUpgrade libavformat58_76Upgrade libavcodec58_134Upgrade ffmpeg-4-libswscale-develUpgrade libswscale5_9Upgrade ffmpeg-4-libswresample-develUpgrade ffmpeg-4-libavfilter-develUpgrade libpostproc55_9Upgrade libavformat61Upgrade libavfilter7_110Upgrade ffmpeg-7Upgrade ffmpeg-4-libavformat-develUpgrade libpostproc55_9-32bitUpgrade libavdevice61Upgrade libswresample3_9-32bitUpgrade libavformat58_76-32bitUpgrade libavutil56_70Upgrade libavresample4_0-32bitUpgrade ffmpeg-4-libavresample-devel | Dec 30, 2024 | Aug 6, 2024 |
| Ubuntu | — | Upgrade ffmpeg (Ubuntu Pro)Upgrade libavcodec-dev (Ubuntu Pro) | Jun 26, 2025 | Aug 6, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub