CVE-2024-36613

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-36613
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-36613.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-36613
Related
Published
2025-01-03T18:15:15Z
Modified
2025-01-15T05:15:57.153281Z
Summary
[none]
Details

FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.

References

Affected packages

Debian:11 / ffmpeg

Package

Name
ffmpeg
Purl
pkg:deb/debian/ffmpeg?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7:4.3.7-0+deb11u1

Affected versions

7:4.*

7:4.3.2-0+deb11u2
7:4.3.2-1
7:4.3.2-2
7:4.3.3-0+deb11u1
7:4.3.4-0+deb11u1
7:4.3.5-0+deb11u1
7:4.3.6-0+deb11u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / ffmpeg

Package

Name
ffmpeg
Purl
pkg:deb/debian/ffmpeg?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7:5.1.5-0+deb12u1

Affected versions

7:5.*

7:5.1.3-1
7:5.1.3-2
7:5.1.4-0+deb12u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / ffmpeg

Package

Name
ffmpeg
Purl
pkg:deb/debian/ffmpeg?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7:7.0.1-3

Affected versions

7:5.*

7:5.1.3-1
7:5.1.3-2

7:6.*

7:6.0-1
7:6.0-2
7:6.0-3
7:6.0-4
7:6.0-5
7:6.0-6
7:6.0-7
7:6.0-8
7:6.0-9
7:6.1-1
7:6.1-2
7:6.1-3
7:6.1-4
7:6.1-5
7:6.1.1-1
7:6.1.1-2
7:6.1.1-3
7:6.1.1-4
7:6.1.1-5

7:7.*

7:7.0-1
7:7.0.1-1
7:7.0.1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/ffmpeg/ffmpeg

Affected ranges

Type
GIT
Repo
https://github.com/ffmpeg/ffmpeg
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

N

n0.*

n0.11-dev
n0.12-dev
n0.8

n1.*

n1.1-dev
n1.2-dev
n1.3-dev

n2.*

n2.0
n2.1-dev
n2.2-dev
n2.3-dev
n2.4-dev
n2.5-dev
n2.6-dev
n2.7-dev
n2.8-dev
n2.9-dev

n3.*

n3.1-dev
n3.2-dev
n3.3-dev
n3.4-dev
n3.5-dev

n4.*

n4.1-dev
n4.2-dev
n4.3-dev
n4.4-dev
n4.5-dev

n5.*

n5.1-dev
n5.2-dev

n6.*

n6.1-dev
n6.2-dev