Logo
vulnerabilityCVE-2022-2566
Name
CVE-2022-2566
Source
NVD ( link)Debian ( link)
Description
A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a small allocation with `av_calloc()`. An attacker can cause remote code execution via a malicious mp4 file. We recommend upgrading past commit c953baa084607dd1d84c3bfcce3cf6a87c3e6e05
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
ffmpeg
Not Affected

Vulnerability Ratings#


9
CVSSv31
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.1.5
Not Affected
buildroot
master
6.1.5
Not Affected
openwrt
master
6.1.4-r2
Not Affected
openwrt
openwrt-25.12
6.1.4-r1
Not Affected
yocto
kirkstone
5.0.3
Not Affected
yocto
scarthgap
6.1.4
Not Affected