Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the jpegxlanimread_packet component in the JPEG XL Animation decoder.
[
{
"id": "CVE-2024-22860-0f557012",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"53488719704562141814838009937693765856",
"304883868025902907842664262674585853251",
"337951878287262195046649855814749687367",
"195604420235369802659487413543457347390"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/ffmpeg/ffmpeg/commit/d2e8974699a9e35cc1a926bf74a972300d629cd5",
"target": {
"file": "libavformat/jpegxl_anim_dec.c"
}
},
{
"id": "CVE-2024-22860-e7d16ad1",
"signature_version": "v1",
"digest": {
"length": 685.0,
"function_hash": "88129333516993045956772730340786749034"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://github.com/ffmpeg/ffmpeg/commit/d2e8974699a9e35cc1a926bf74a972300d629cd5",
"target": {
"file": "libavformat/jpegxl_anim_dec.c",
"function": "jpegxl_anim_read_packet"
}
}
]