#VU92205 Out-of-bounds write in FFmpeg - CVE-2023-47470
Published: June 18, 2024
FFmpeg
ffmpeg.sourceforge.net
Description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input. A local user can create a specially crafted file, trick the victim into opening it using the affected software, achieve an out-of-array write, execute arbitrary code, and cause a denial of service (DoS) via the ref_pic_list_struct function in libavcodec/evc_ps.c