Description

FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without proper bounds checking.

INFO

Published Date :

2024-11-29T00:00:00.000Z

Last Modified :

2024-12-03T14:11:35.604Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-35366 vulnerability.

Vendors Products
Ffmpeg
  • Ffmpeg

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact