Logo
vulnerabilityCVE-2023-6604
Name
CVE-2023-6604
Source
NVD ( link)Debian ( link)
Description
A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
ffmpeg
Patched

Vulnerability Ratings#


5.3
CVSSv31
5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.1.5
Not Affected
buildroot
master
6.1.5
Not Affected
openwrt
master
6.1.4-r2
Not Affected
openwrt
openwrt-25.12
6.1.4-r1
Not Affected
yocto
master
8.1.1
Not Affected
yocto
scarthgap
6.1.4
Not Affected

Resolved with patches#


ffmpeg (yocto:kirkstone)

#
Title
Author
Resolve
1
avformat/dashdec: Check whitelist
Michael Niedermayer <michael@niedermayer.cc>
CVE-2023-6602
CVE-2023-6604
2
avformat/hls: Be more picky on extensions
Michael Niedermayer <michael@niedermayer.cc>
CVE-2023-6601
CVE-2023-6602
CVE-2023-6604
CVE-2023-6605
3
avformat: add ff_match_url_ext()
Michael Niedermayer <michael@niedermayer.cc>
CVE-2023-6602
CVE-2023-6604
CVE-2023-6605