MEDIUM
ffmpeg: FFmpeg: Integer overflow in DXA demuxer leads to denial of service
Published Jan 3, 2025
6.2
MEDIUMCVSS 3.1
EPSS 0.28%
Description
FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.
Affected products
Remediation
Red Hat statement
This vulnerability doesn't affect any supported Red Hat product.
Weaknesses (1)
References (7)
- https://access.redhat.com/security/cve/CVE-2024-36613 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2335448 Issue Tracking
- https://gist.github.com/1047524396/0f4d90ef87553f772f888223085ac806 Third Party Advisory
- https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/dxa.c#L125 Product
- https://github.com/ffmpeg/ffmpeg/commit/50d8e4f27398fd5778485a827d7a2817921f8540 Patch
- https://nvd.nist.gov/vuln/detail/CVE-2024-36613
- https://www.cve.org/CVERecord?id=CVE-2024-36613
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 3, 2025
Updated Jan 3, 2025
Reserved May 30, 2024
Link CVE-2024-36613
CISA Vulnrichment
Updated Jan 3, 2025