PT-2026-64415 · FFmpeg+3 · Ffmpeg+3
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions prior to 8.1.2
Description
The MACE6 audio decoder contains a signed integer overflow that allows heap memory corruption via a crafted CAF file. By providing oversized
bytes per packet and frames per packet values in the desc chunk, an attacker can trigger an integer overflow in the mace decode frame() function during the computation of the output sample count. This leads to an undersized buffer allocation and a heap out-of-bounds write, which could potentially enable arbitrary code execution.Recommendations
Update to the version containing commit aafb5c6.
As a temporary mitigation, avoid processing CAF files using the MACE6 audio decoder.
Exploit
Fix
DoS
Heap Based Buffer Overflow
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ffmpeg
Linuxmint
Red Os
Ubuntu