CVE-2024-36618

FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) condition.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ffmpeg:ffmpeg:6.1.1:*:*:*:*:*:*:*

History

03 Jun 2025, 16:05

Type Values Removed Values Added
CPE cpe:2.3:a:ffmpeg:ffmpeg:6.1.1:*:*:*:*:*:*:*
First Time Ffmpeg ffmpeg
Ffmpeg
References () https://gist.github.com/1047524396/a148f3679415a6da53ca112eb2ba1523 - () https://gist.github.com/1047524396/a148f3679415a6da53ca112eb2ba1523 - Third Party Advisory
References () https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/avidec.c#L1699 - () https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/avidec.c#L1699 - Product
References () https://github.com/ffmpeg/ffmpeg/commit/7a089ed8e049e3bfcb22de1250b86f2106060857 - () https://github.com/ffmpeg/ffmpeg/commit/7a089ed8e049e3bfcb22de1250b86f2106060857 - Patch

02 Dec 2024, 18:15

Type Values Removed Values Added
Summary
  • (es) FFmpeg n6.1.1 tiene una vulnerabilidad en el demuxer AVI de la librería libavformat que permite un desbordamiento de enteros, lo que potencialmente resulta en una condición de denegación de servicio (DoS).
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.2
CWE CWE-190

29 Nov 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-29 18:15

Updated : 2025-06-03 16:05


NVD link : CVE-2024-36618

Mitre link : CVE-2024-36618

CVE.ORG link : CVE-2024-36618


JSON object : View

Products Affected

ffmpeg

  • ffmpeg
CWE
CWE-190

Integer Overflow or Wraparound