Logo
vulnerabilityCVE-2024-35366
Name
CVE-2024-35366
Source
NVD ( link)Debian ( link)
Description
FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without proper bounds checking.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
ffmpeg
Patched

Vulnerability Ratings#


9.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.1.5
Not Affected
buildroot
master
6.1.5
Not Affected
openwrt
master
6.1.4-r2
Not Affected
openwrt
openwrt-25.12
6.1.4-r1
Not Affected
yocto
master
8.1.1
Not Affected
yocto
scarthgap
6.1.4
Not Affected

Resolved with patches#


ffmpeg (yocto:kirkstone)

#
Title
Author
Resolve
1
avformat/sbgdec: Check for negative duration
Michael Niedermayer <michael@niedermayer.cc>
CVE-2024-35366