Logo
vulnerabilityCVE-2025-1594
Name
CVE-2025-1594
Source
NVD ( link)Debian ( link)
Description
A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
ffmpeg
Exploitable

Vulnerability Ratings#


5.3
CVSSv4
6.3
CVSSv31
8.8
CVSSv31
7.5
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.1.5
Exploitable
buildroot
master
6.1.5
Exploitable
openwrt
master
6.1.4-r2
Exploitable
openwrt
openwrt-25.12
6.1.4-r1
Exploitable
yocto
kirkstone
5.0.3
Patched
yocto
master
8.1.1
Not Affected

Resolved with patches#


ffmpeg (yocto:kirkstone)

#
Title
Author
Resolve
1
aacenc_tns: clamp filter direction energy measurement
Lynne <dev@lynne.ee>
CVE-2025-1594