Out-of-bounds read in FFmpeg - CVE-2023-46407
Published: June 18, 2024
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in the dist->alphabet_size variable in the read_vlc_prefix() function. A local user can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory on the system.
Affected software
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
How to mitigate CVE-2023-46407
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405