Logo
vulnerabilityCVE-2023-39018
Name
CVE-2023-39018
Source
NVD ( link)Debian ( link)
Description
FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no realistic use cases in which FFmpeg.java uses untrusted input for the path of the executable file.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
ffmpeg
False Positive

Vulnerability Ratings#


9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.1.5
Not Affected
buildroot
master
6.1.5
Not Affected
openwrt
master
6.1.4-r2
Not Affected
openwrt
openwrt-25.12
6.1.4-r1
Not Affected
yocto
kirkstone
5.0.3
Not Affected
yocto
master
8.1.1
Not Affected