跳转到帖子

Debian: CVE-2024-35366: ffmpeg -- security update

recommended_posts

发布于
  • Members

Debian: CVE-2024-35366: ffmpeg -- security update

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
11/29/2024
Created
12/10/2024
Added
12/09/2024
Modified
12/09/2024

Description

FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without proper bounds checking.

Solution(s)

  • debian-upgrade-ffmpeg

References

  • https://attackerkb.com/topics/cve-2024-35366
  • CVE - 2024-35366
  • DSA-5712-1
  • 查看数 696
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…