Integer overflow in FFmpeg - CVE-2024-22862
Published: June 18, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow. A remote attacker can pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the target system via the JJPEG XL Parser.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Telemetry Dashboard
IBM Watson Machine Learning Accelerator
Liquidware
Citrix Workspace App
Webex App VDI
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
How to mitigate CVE-2024-22862
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
IBM Watson Machine Learning Accelerator - update to 5.0.3
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405