Integer overflow in FFmpeg - CVE-2024-22861

 

Integer overflow in FFmpeg - CVE-2024-22861

Published: June 18, 2024


Vulnerability identifier: #VU92211
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22861
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to integer overflow in the avcodec/osq module. A remote attacker can pass specially crafted data to the application, trigger integer overflow and perform a denial of service attack on the target system.


Affected software

FFmpeg
Telemetry Dashboard
IBM Watson Machine Learning Accelerator
Liquidware
Citrix Workspace App
Webex App VDI
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client

How to mitigate CVE-2024-22861

Install updates from vendor's website.

FFmpeg - update to 6.1
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
IBM Watson Machine Learning Accelerator - update to 5.0.3
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405

External References

Related Security Bulletins