PT-2025-6903 · FFmpeg · Ffmpeg
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
FFmpeg versions prior to 7.1
Description:
A problem has been found in the function
mov read trak of the file libavformat/mov.c of the component MOV Parser. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.Recommendations:
For FFmpeg versions prior to 7.1, apply a patch to fix this issue. As a temporary workaround, consider restricting access to the
mov read trak function of the MOV Parser component until a patch is available.Exploit
Fix
NULL Pointer Dereference
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ffmpeg