CVE-2024-31578 Affecting ffmpeg package, versions *
Threat Intelligence
EPSS
0.05% (17th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UBUNTU2004-FFMPEG-6670103
- published 31 May 2024
- disclosed 17 Apr 2024
Introduced: 17 Apr 2024
CVE-2024-31578 Open this link in a new tabHow to fix?
There is no fixed version for Ubuntu:20.04 ffmpeg.
NVD Description
Note: Versions mentioned in the description apply only to the upstream ffmpeg package and not the ffmpeg package as distributed by Ubuntu.
See How to fix? for Ubuntu:20.04 relevant fixed versions and status.
FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.
References
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2024-31578
- https://gist.github.com/1047524396/45400cce5859d78dcd3a62010df8d179
- https://github.com/ffmpeg/ffmpeg/commit/3bb00c0a420c3ce83c6fafee30270d69622ccad7
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/
CVSS Scores
version 3.1