Logo
vulnerabilityCVE-2024-7055
Name
CVE-2024-7055
Source
NVD ( link)Debian ( link)
Description
A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.2 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-273651.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
ffmpeg
Patched

Vulnerability Ratings#


6.9
CVSSv4
6.3
CVSSv31
8.8
CVSSv31
7.5
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.1.5
Not Affected
buildroot
master
6.1.5
Not Affected
openwrt
master
6.1.4-r2
Not Affected
openwrt
openwrt-25.12
6.1.4-r1
Not Affected
yocto
master
8.1.1
Not Affected
yocto
scarthgap
6.1.4
Not Affected

Resolved with patches#


ffmpeg (yocto:kirkstone)

#
Title
Author
Resolve
1
avcodec/pnmdec: Use 64bit for input size check
Michael Niedermayer <michael@niedermayer.cc>
CVE-2024-7055