
Cloud Vulnerability DB
A community-led vulnerabilities database
FFmpeg version n6.1 contains a heap buffer overflow vulnerability in the draw_block_rectangle function located in libavfilter/vf_codecview.c. The vulnerability was discovered and disclosed on April 17, 2024 (NVD).
The vulnerability exists in the draw_block_rectangle function of libavfilter/vf_codecview.c and has been assigned a CVSS v3.1 base score of 7.8 HIGH (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). The issue is classified as a CWE-122: Heap-based Buffer Overflow vulnerability (NVD).
When exploited, this vulnerability allows attackers to cause undefined behavior or a Denial of Service (DoS) through crafted input. The high CVSS score indicates potential severe impacts on system confidentiality, integrity, and availability (NVD).
The vulnerability can be triggered via crafted input that targets the draw_block_rectangle function. The attack requires local access and user interaction, as indicated by the CVSS metrics (NVD).
A fix has been implemented and is available in the FFmpeg commit 99debe5f823f45a482e1dc08de35879aa9c74bd2. Ubuntu has released fixes for affected versions in Ubuntu 23.10 (version 7:6.0-6ubuntu1.1) and Ubuntu 24.04 LTS (version 7:6.1.1-3ubuntu5+esm1) (Ubuntu).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."