CVE Published: 23/09/2022 |
CVE Updated: 17/09/2024 |
CVE Year: 2022 Source: Google |
Vendor: FFMPEG |
Product: FFMPEG Status : PUBLISHED
CVE-2022-2566 Description
A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a small allocation with `av_calloc()`. An attacker can cause remote code execution via a malicious mp4 file. We recommend upgrading past commit c953baa084607dd1d84c3bfcce3cf6a87c3e6e05
Metrics
CVSS Version: 3.1 |
Base Score: 9 CRITICAL Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H