FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
{ "vanir_signatures": [ { "signature_version": "v1", "signature_type": "Line", "target": { "file": "libavformat/cafdec.c" }, "deprecated": false, "digest": { "line_hashes": [ "44973636752222320202739228100696163360", "274436137156896354455671107439876243104", "184972138392671777370760264547244923719", "236992614078391776037833767438845251703" ], "threshold": 0.9 }, "id": "CVE-2024-36617-1c8c6403", "source": "https://github.com/ffmpeg/ffmpeg/commit/d973fcbcc2f944752ff10e6a76b0b2d9329937a7" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "libavformat/cafdec.c", "function": "read_pakt_chunk" }, "deprecated": false, "digest": { "length": 1265.0, "function_hash": "82835186559573989995264497669114067249" }, "id": "CVE-2024-36617-b1262d81", "source": "https://github.com/ffmpeg/ffmpeg/commit/d973fcbcc2f944752ff10e6a76b0b2d9329937a7" } ] }