Rapid7

vulnerability

FFmpeg: CVE-2024-36613: Integer Overflow or Wraparound

Severity
5
CVSS
(AV:L/AC:L/Au:N/C:N/I:N/A:C)
Published
Jan 3, 2025
Added
Jun 5, 2025
Modified
Jun 4, 2026

Description

FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.

Solutions

ffmpeg-upgrade-4_3_7ffmpeg-upgrade-5_1_5ffmpeg-upgrade-7_0
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.