Integer overflow in FFmpeg - CVE-2022-1475
Published: December 27, 2023
Vulnerability identifier: #VU84803
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1475
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to crash the application.
The vulnerability exists due to integer overflow within the g729_parse() function in llibavcodec/g729_parser.c. A remote attacker can trick the victim to open a specially crafted file and crash the application.
Affected software
FFmpeg
Gentoo Linux
Slackware Linux
openEuler
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
ffmpeg
libavdevice
ffmpeg-libs
ffmpeg-devel
ffmpeg-debugsource
ffmpeg-debuginfo
Gentoo Linux
Slackware Linux
openEuler
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
ffmpeg
libavdevice
ffmpeg-libs
ffmpeg-devel
ffmpeg-debugsource
ffmpeg-debuginfo
How to mitigate CVE-2022-1475
Install updates from vendor's website.
FFmpeg - addressed in versions 4.4.2, 5.0.1
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
ffmpeg - update to 4.2.4-17
libavdevice - update to 4.2.4-17
ffmpeg-libs - update to 4.2.4-17
ffmpeg-devel - update to 4.2.4-17
ffmpeg-debugsource - update to 4.2.4-17
ffmpeg-debuginfo - update to 4.2.4-17
ffmpeg - update to 4.4.5
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
ffmpeg - update to 4.2.4-17
libavdevice - update to 4.2.4-17
ffmpeg-libs - update to 4.2.4-17
ffmpeg-devel - update to 4.2.4-17
ffmpeg-debugsource - update to 4.2.4-17
ffmpeg-debuginfo - update to 4.2.4-17
ffmpeg - update to 4.4.5