Integer overflow in FFmpeg - CVE-2024-36617

 

Integer overflow in FFmpeg - CVE-2024-36617

Published: December 20, 2024


Vulnerability identifier: #VU101884
CSH Severity: High
CVSS v4 BT: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2024-36617
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow within CAF decoder. A remote attacker can pass specially crafted file to the application, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

FFmpeg
Ubuntu
openEuler
libavutil56 (Ubuntu package)
libavfilter-extra6 (Ubuntu package)
libavdevice57 (Ubuntu package)
libavcodec57 (Ubuntu package)
libavcodec-extra57 (Ubuntu package)
libavresample4 (Ubuntu package)
libswscale5 (Ubuntu package)
libswresample3 (Ubuntu package)
libpostproc55 (Ubuntu package)
libavfilter6 (Ubuntu package)
libavformat58 (Ubuntu package)
libavformat-extra58 (Ubuntu package)
ffmpeg (Ubuntu package)
libavcodec-extra58 (Ubuntu package)
libavcodec58 (Ubuntu package)
libavdevice58 (Ubuntu package)
libavfilter-extra7 (Ubuntu package)
libavfilter7 (Ubuntu package)
libavcodec-ffmpeg56 (Ubuntu package)
libswscale-ffmpeg3 (Ubuntu package)
libswresample-ffmpeg1 (Ubuntu package)
libpostproc-ffmpeg53 (Ubuntu package)
libavutil-ffmpeg54 (Ubuntu package)
libavresample-ffmpeg2 (Ubuntu package)
libavformat-ffmpeg56 (Ubuntu package)
libavfilter-ffmpeg5 (Ubuntu package)
libavdevice-ffmpeg56 (Ubuntu package)
libavcodec-ffmpeg-extra56 (Ubuntu package)
libav-tools (Ubuntu package)
libswscale4 (Ubuntu package)
libswresample2 (Ubuntu package)
libpostproc54 (Ubuntu package)
libavutil55 (Ubuntu package)
libavresample3 (Ubuntu package)
libavformat57 (Ubuntu package)
ffmpeg-debuginfo
ffmpeg-libs
ffmpeg
ffmpeg-debugsource
ffmpeg-devel
libavdevice

How to mitigate CVE-2024-36617

Install updates from vendor's website.

FFmpeg - update to 7.0
libavutil56 (Ubuntu package) - update to Ubuntu Pro
libavfilter-extra6 (Ubuntu package) - update to Ubuntu Pro
libavdevice57 (Ubuntu package) - update to Ubuntu Pro
libavcodec57 (Ubuntu package) - update to Ubuntu Pro
libavcodec-extra57 (Ubuntu package) - update to Ubuntu Pro
libavresample4 (Ubuntu package) - update to Ubuntu Pro
libswscale5 (Ubuntu package) - update to Ubuntu Pro
libswresample3 (Ubuntu package) - update to Ubuntu Pro
libpostproc55 (Ubuntu package) - update to Ubuntu Pro
libavfilter6 (Ubuntu package) - update to Ubuntu Pro
libavformat58 (Ubuntu package) - update to Ubuntu Pro
libavformat-extra58 (Ubuntu package) - update to Ubuntu Pro
ffmpeg (Ubuntu package) - addressed in versions Ubuntu Pro, 7:6.1.1-3ubuntu5+esm8
libavcodec-extra58 (Ubuntu package) - update to Ubuntu Pro
libavcodec58 (Ubuntu package) - update to Ubuntu Pro
libavdevice58 (Ubuntu package) - update to Ubuntu Pro
libavfilter-extra7 (Ubuntu package) - update to Ubuntu Pro
libavfilter7 (Ubuntu package) - update to Ubuntu Pro
libavcodec-ffmpeg56 (Ubuntu package) - update to Ubuntu Pro
libswscale-ffmpeg3 (Ubuntu package) - update to Ubuntu Pro
libswresample-ffmpeg1 (Ubuntu package) - update to Ubuntu Pro
libpostproc-ffmpeg53 (Ubuntu package) - update to Ubuntu Pro
libavutil-ffmpeg54 (Ubuntu package) - update to Ubuntu Pro
libavresample-ffmpeg2 (Ubuntu package) - update to Ubuntu Pro
libavformat-ffmpeg56 (Ubuntu package) - update to Ubuntu Pro
libavfilter-ffmpeg5 (Ubuntu package) - update to Ubuntu Pro
libavdevice-ffmpeg56 (Ubuntu package) - update to Ubuntu Pro
libavcodec-ffmpeg-extra56 (Ubuntu package) - update to Ubuntu Pro
libav-tools (Ubuntu package) - update to Ubuntu Pro
libswscale4 (Ubuntu package) - update to Ubuntu Pro
libswresample2 (Ubuntu package) - update to Ubuntu Pro
libpostproc54 (Ubuntu package) - update to Ubuntu Pro
libavutil55 (Ubuntu package) - update to Ubuntu Pro
libavresample3 (Ubuntu package) - update to Ubuntu Pro
libavformat57 (Ubuntu package) - update to Ubuntu Pro
ffmpeg-debuginfo - addressed in versions 4.2.4-21, 6.1.1-17
ffmpeg-libs - addressed in versions 4.2.4-21, 6.1.1-17
ffmpeg - addressed in versions 4.2.4-21, 6.1.1-17
ffmpeg-debugsource - addressed in versions 4.2.4-21, 6.1.1-17
ffmpeg-devel - addressed in versions 4.2.4-21, 6.1.1-17
libavdevice - addressed in versions 4.2.4-21, 6.1.1-17

External References

Related Security Bulletins