Heap-based buffer overflow in FFmpeg - CVE-2023-51794

 

Heap-based buffer overflow in FFmpeg - CVE-2023-51794

Published: July 11, 2024


Vulnerability identifier: #VU94116
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2023-51794
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
FFmpeg
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Package Hub 15
Desktop Applications Module
openSUSE Leap
Ubuntu
libswscale5 (Ubuntu package)
libswscale4 (Ubuntu package)
libavcodec-extra58 (Ubuntu package)
libavcodec58 (Ubuntu package)
libavdevice58 (Ubuntu package)
libavfilter-extra7 (Ubuntu package)
libavfilter7 (Ubuntu package)
libavformat-extra (Ubuntu package)
libavformat-extra58 (Ubuntu package)
libavformat58 (Ubuntu package)
libavutil56 (Ubuntu package)
libpostproc55 (Ubuntu package)
libswresample3 (Ubuntu package)
libswscale7 (Ubuntu package)
libavresample4 (Ubuntu package)
libavcodec-extra57 (Ubuntu package)
libavcodec57 (Ubuntu package)
libavdevice57 (Ubuntu package)
libavfilter-extra6 (Ubuntu package)
libavfilter6 (Ubuntu package)
libavformat57 (Ubuntu package)
libavresample3 (Ubuntu package)
libavutil55 (Ubuntu package)
libpostproc54 (Ubuntu package)
libswresample2 (Ubuntu package)
libavcodec-ffmpeg-extra56 (Ubuntu package)
ffmpeg (Ubuntu package)
libavcodec-extra60 (Ubuntu package)
libswscale-ffmpeg3 (Ubuntu package)
libavcodec60 (Ubuntu package)
libswresample-ffmpeg1 (Ubuntu package)
libavdevice60 (Ubuntu package)
libpostproc-ffmpeg53 (Ubuntu package)
libavfilter-extra9 (Ubuntu package)
libavutil-ffmpeg54 (Ubuntu package)
libavfilter9 (Ubuntu package)
libavresample-ffmpeg2 (Ubuntu package)
libavformat-extra60 (Ubuntu package)
libavformat-ffmpeg56 (Ubuntu package)
libavformat60 (Ubuntu package)
libavfilter-ffmpeg5 (Ubuntu package)
libavutil58 (Ubuntu package)
libavdevice-ffmpeg56 (Ubuntu package)
libpostproc57 (Ubuntu package)
libavcodec-ffmpeg56 (Ubuntu package)
libswresample4 (Ubuntu package)
libavresample3-32bit
libavcodec57-32bit
libavformat57-debuginfo
libavfilter-devel
libavdevice-devel
ffmpeg-private-devel
libavformat-devel
libavcodec-devel
libavresample-devel
libavresample3-debuginfo
libavformat57
libavdevice57
ffmpeg
libavresample3
libavdevice57-debuginfo
libavformat57-32bit
libpostproc54-32bit
libpostproc54-32bit-debuginfo
libavfilter6-32bit
libavutil55-32bit
libswscale4-32bit-debuginfo
libavutil55-32bit-debuginfo
libswresample2-32bit
libavcodec57-32bit-debuginfo
libavformat57-32bit-debuginfo
libavdevice57-32bit-debuginfo
libswscale4-32bit
libswresample2-32bit-debuginfo
libavresample3-32bit-debuginfo
libavdevice57-32bit
libavfilter6-32bit-debuginfo
libavfilter6
libavcodec57-debuginfo
libavutil55
ffmpeg-debugsource
libavutil55-debuginfo
libswscale4
libswresample-devel
libpostproc-devel
libswscale4-debuginfo
libpostproc54-debuginfo
libavcodec57
libpostproc54
libavutil-devel
ffmpeg-debuginfo
libswresample2-debuginfo
libswresample2
libavfilter6-debuginfo
libswscale-devel
ffmpeg (Debian package)

Detailed vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in libavfilter/af_stereowiden.c. A remote attacker can pass specially crafted media file to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


How to mitigate CVE-2023-51794

Install updates from vendor's website.

Sources