Integer overflow in FFmpeg - CVE-2024-36618
Published: December 20, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow within the libavformat library in AVI demuxer. A remote attacker can pass specially crafted file to the application, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
openSUSE Leap
Ubuntu
openEuler
ffmpeg (Ubuntu package)
ffmpeg-debuginfo
libavdevice
ffmpeg-libs
ffmpeg-devel
ffmpeg-debugsource
ffmpeg
libavutil56_70-64bit-debuginfo
libswresample3_9-32bit
libavresample4_0-32bit
libavcodec58_134-32bit
libavfilter7_110-32bit
libavcodec58_134-32bit-debuginfo
libswscale5_9-32bit
libavdevice58_13-32bit-debuginfo
libavutil56_70-32bit-debuginfo
libswscale5_9-32bit-debuginfo
libavresample4_0-32bit-debuginfo
libavutil56_70-32bit
libavfilter7_110-32bit-debuginfo
libavformat58_76-32bit-debuginfo
libavdevice58_13-32bit
libswresample3_9-32bit-debuginfo
libavformat58_76-32bit
libpostproc55_9-32bit
libavcodec58_134-64bit-debuginfo
libavresample4_0-64bit
libavresample4_0-64bit-debuginfo
libavdevice58_13-64bit
libavcodec58_134-64bit
libavdevice58_13-64bit-debuginfo
libswscale5_9-64bit
libavfilter7_110-64bit-debuginfo
libavformat58_76-64bit
libavfilter7_110-64bit
libswresample3_9-64bit-debuginfo
libavutil56_70-64bit
libswscale5_9-64bit-debuginfo
libpostproc55_9-64bit
libpostproc55_9-64bit-debuginfo
libavformat58_76-64bit-debuginfo
libswresample3_9-64bit
libavcodec58_134
libswresample3_9-debuginfo
libavcodec58_134-debuginfo
ffmpeg-4-libavresample-devel
libavutil56_70
ffmpeg-4-debugsource
libavdevice58_13-debuginfo
ffmpeg-4-libavutil-devel
ffmpeg-4-libswresample-devel
libpostproc55_9-32bit-debuginfo
libavutil56_70-debuginfo
libavformat58_76-debuginfo
ffmpeg-4-libavdevice-devel
libavformat58_76
libswscale5_9
ffmpeg-4-private-devel
ffmpeg-4
libavdevice58_13
ffmpeg-4-debuginfo
libavresample4_0
libswscale5_9-debuginfo
ffmpeg-4-libavformat-devel
libavfilter7_110
ffmpeg-4-libavcodec-devel
ffmpeg-4-libswscale-devel
libswresample3_9
libpostproc55_9-debuginfo
ffmpeg-4-libavfilter-devel
libavfilter7_110-debuginfo
libavresample4_0-debuginfo
libpostproc55_9
ffmpeg-4-libpostproc-devel
How to mitigate CVE-2024-36618
ffmpeg (Ubuntu package) - addressed in versions 7:2.8.17-0ubuntu0.1+esm12, 7:3.4.11-0ubuntu0.1+esm10, 7:4.2.7-0ubuntu0.1+esm10, 7:4.4.2-0ubuntu0.22.04.1+esm9, 7:6.1.1-3ubuntu5+esm5
ffmpeg-debuginfo - addressed in versions 4.2.4-21, 6.1.1-17
libavdevice - addressed in versions 4.2.4-21, 6.1.1-17
ffmpeg-libs - addressed in versions 4.2.4-21, 6.1.1-17
ffmpeg-devel - addressed in versions 4.2.4-21, 6.1.1-17
ffmpeg-debugsource - addressed in versions 4.2.4-21, 6.1.1-17
ffmpeg - addressed in versions 4.2.4-21, 6.1.1-17
libavutil56_70-64bit-debuginfo - update to 4.4.6-150400.3.52.1
libswresample3_9-32bit - update to 4.4.6-150400.3.52.1
libavresample4_0-32bit - update to 4.4.6-150400.3.52.1
libavcodec58_134-32bit - update to 4.4.6-150400.3.52.1
libavfilter7_110-32bit - update to 4.4.6-150400.3.52.1
libavcodec58_134-32bit-debuginfo - update to 4.4.6-150400.3.52.1
libswscale5_9-32bit - update to 4.4.6-150400.3.52.1
libavdevice58_13-32bit-debuginfo - update to 4.4.6-150400.3.52.1
libavutil56_70-32bit-debuginfo - update to 4.4.6-150400.3.52.1
libswscale5_9-32bit-debuginfo - update to 4.4.6-150400.3.52.1
libavresample4_0-32bit-debuginfo - update to 4.4.6-150400.3.52.1
libavutil56_70-32bit - update to 4.4.6-150400.3.52.1
libavfilter7_110-32bit-debuginfo - update to 4.4.6-150400.3.52.1
libavformat58_76-32bit-debuginfo - update to 4.4.6-150400.3.52.1
libavdevice58_13-32bit - update to 4.4.6-150400.3.52.1
libswresample3_9-32bit-debuginfo - update to 4.4.6-150400.3.52.1
libavformat58_76-32bit - update to 4.4.6-150400.3.52.1
libpostproc55_9-32bit - update to 4.4.6-150400.3.52.1
libavcodec58_134-64bit-debuginfo - update to 4.4.6-150400.3.52.1
libavresample4_0-64bit - update to 4.4.6-150400.3.52.1
libavresample4_0-64bit-debuginfo - update to 4.4.6-150400.3.52.1
libavdevice58_13-64bit - update to 4.4.6-150400.3.52.1
libavcodec58_134-64bit - update to 4.4.6-150400.3.52.1
libavdevice58_13-64bit-debuginfo - update to 4.4.6-150400.3.52.1
libswscale5_9-64bit - update to 4.4.6-150400.3.52.1
libavfilter7_110-64bit-debuginfo - update to 4.4.6-150400.3.52.1
libavformat58_76-64bit - update to 4.4.6-150400.3.52.1
libavfilter7_110-64bit - update to 4.4.6-150400.3.52.1
libswresample3_9-64bit-debuginfo - update to 4.4.6-150400.3.52.1
libavutil56_70-64bit - update to 4.4.6-150400.3.52.1
libswscale5_9-64bit-debuginfo - update to 4.4.6-150400.3.52.1
libpostproc55_9-64bit - update to 4.4.6-150400.3.52.1
libpostproc55_9-64bit-debuginfo - update to 4.4.6-150400.3.52.1
libavformat58_76-64bit-debuginfo - update to 4.4.6-150400.3.52.1
libswresample3_9-64bit - update to 4.4.6-150400.3.52.1
libavcodec58_134 - update to 4.4.6-150400.3.52.1
libswresample3_9-debuginfo - update to 4.4.6-150400.3.52.1
libavcodec58_134-debuginfo - update to 4.4.6-150400.3.52.1
ffmpeg-4-libavresample-devel - update to 4.4.6-150400.3.52.1
libavutil56_70 - update to 4.4.6-150400.3.52.1
ffmpeg-4-debugsource - update to 4.4.6-150400.3.52.1
libavdevice58_13-debuginfo - update to 4.4.6-150400.3.52.1
ffmpeg-4-libavutil-devel - update to 4.4.6-150400.3.52.1
ffmpeg-4-libswresample-devel - update to 4.4.6-150400.3.52.1
libpostproc55_9-32bit-debuginfo - update to 4.4.6-150400.3.52.1
libavutil56_70-debuginfo - update to 4.4.6-150400.3.52.1
libavformat58_76-debuginfo - update to 4.4.6-150400.3.52.1
ffmpeg-4-libavdevice-devel - update to 4.4.6-150400.3.52.1
libavformat58_76 - update to 4.4.6-150400.3.52.1
libswscale5_9 - update to 4.4.6-150400.3.52.1
ffmpeg-4-private-devel - update to 4.4.6-150400.3.52.1
ffmpeg-4 - update to 4.4.6-150400.3.52.1
libavdevice58_13 - update to 4.4.6-150400.3.52.1
ffmpeg-4-debuginfo - update to 4.4.6-150400.3.52.1
libavresample4_0 - update to 4.4.6-150400.3.52.1
libswscale5_9-debuginfo - update to 4.4.6-150400.3.52.1
ffmpeg-4-libavformat-devel - update to 4.4.6-150400.3.52.1
libavfilter7_110 - update to 4.4.6-150400.3.52.1
ffmpeg-4-libavcodec-devel - update to 4.4.6-150400.3.52.1
ffmpeg-4-libswscale-devel - update to 4.4.6-150400.3.52.1
libswresample3_9 - update to 4.4.6-150400.3.52.1
libpostproc55_9-debuginfo - update to 4.4.6-150400.3.52.1
ffmpeg-4-libavfilter-devel - update to 4.4.6-150400.3.52.1
libavfilter7_110-debuginfo - update to 4.4.6-150400.3.52.1
libavresample4_0-debuginfo - update to 4.4.6-150400.3.52.1
libpostproc55_9 - update to 4.4.6-150400.3.52.1
ffmpeg-4-libpostproc-devel - update to 4.4.6-150400.3.52.1