Vulnerability Description
FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the read_vlc_prefix() function.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ffmpeg | Ffmpeg | 6.1 |
Related Weaknesses (CWE)
References
- https://github.com/FFmpeg/FFmpeg/commit/bf814387f42e9b0dea9d75c03db4723c88e7d962Patch
- https://patchwork.ffmpeg.org/project/ffmpeg/patch/20231013014959.536776-1-leo.izPatch
- https://patchwork.ffmpeg.org/project/ffmpeg/patch/20231015004924.597746-1-leo.izPatch
- https://github.com/FFmpeg/FFmpeg/commit/bf814387f42e9b0dea9d75c03db4723c88e7d962Patch
- https://patchwork.ffmpeg.org/project/ffmpeg/patch/20231013014959.536776-1-leo.izPatch
- https://patchwork.ffmpeg.org/project/ffmpeg/patch/20231015004924.597746-1-leo.izPatch
FAQ
What is CVE-2023-46407?
CVE-2023-46407 is a vulnerability with a CVSS score of 5.5 (MEDIUM). FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the read_vlc_prefix() function.
How severe is CVE-2023-46407?
CVE-2023-46407 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-46407?
Check the references section above for vendor advisories and patch information. Affected products include: Ffmpeg Ffmpeg.