FFmpeg
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*
- 8.0.1
A heap buffer overflow vulnerability has been identified in FFmpeg version 8.0.1. This vulnerability allows attackers to cause a denial-of-service (DoS) condition by exploiting the av_bprint_finalize() function with crafted input.
Exploitation of this vulnerability leads to a heap buffer overflow, causing a denial-of-service condition.
The vulnerability can be reproduced by sending a crafted input that triggers the heap buffer overflow in the av_bprint_finalize() function. This can be done using the FFmpeg tool 'zmqsend', which sends messages to a ZeroMQ recipient. The 'zmqsend' tool can be used to upload the malicious payload that exploits the vulnerability.
Users are advised to upgrade to FFmpeg versions 8.1 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.