CVE-2024-36618

FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) condition.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ffmpeg:ffmpeg:6.1.1:*:*:*:*:*:*:*

History

03 Jun 2025, 16:05

Type Values Removed Values Added
First Time Ffmpeg ffmpeg
Ffmpeg
References () https://gist.github.com/1047524396/a148f3679415a6da53ca112eb2ba1523 - () https://gist.github.com/1047524396/a148f3679415a6da53ca112eb2ba1523 - Third Party Advisory
References () https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/avidec.c#L1699 - () https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/avidec.c#L1699 - Product
References () https://github.com/ffmpeg/ffmpeg/commit/7a089ed8e049e3bfcb22de1250b86f2106060857 - () https://github.com/ffmpeg/ffmpeg/commit/7a089ed8e049e3bfcb22de1250b86f2106060857 - Patch
CPE cpe:2.3:a:ffmpeg:ffmpeg:6.1.1:*:*:*:*:*:*:*

02 Dec 2024, 18:15

Type Values Removed Values Added
CWE CWE-190
Summary
  • (es) FFmpeg n6.1.1 tiene una vulnerabilidad en el demuxer AVI de la librería libavformat que permite un desbordamiento de enteros, lo que potencialmente resulta en una condición de denegación de servicio (DoS).
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.2

29 Nov 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-29 18:15

Updated : 2025-06-03 16:05


NVD link : CVE-2024-36618

Mitre link : CVE-2024-36618

CVE.ORG link : CVE-2024-36618


JSON object : View

Products Affected

ffmpeg

  • ffmpeg
CWE
CWE-190

Integer Overflow or Wraparound