Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the jpegxlanimread_packet component in the JPEG XL Animation decoder.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-22860.json"
[
{
"digest": {
"line_hashes": [
"53488719704562141814838009937693765856",
"304883868025902907842664262674585853251",
"337951878287262195046649855814749687367",
"195604420235369802659487413543457347390"
],
"threshold": 0.9
},
"target": {
"file": "libavformat/jpegxl_anim_dec.c"
},
"id": "CVE-2024-22860-0f557012",
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/d2e8974699a9e35cc1a926bf74a972300d629cd5",
"signature_version": "v1",
"signature_type": "Line"
},
{
"digest": {
"function_hash": "88129333516993045956772730340786749034",
"length": 685.0
},
"target": {
"file": "libavformat/jpegxl_anim_dec.c",
"function": "jpegxl_anim_read_packet"
},
"id": "CVE-2024-22860-e7d16ad1",
"deprecated": false,
"source": "https://github.com/ffmpeg/ffmpeg/commit/d2e8974699a9e35cc1a926bf74a972300d629cd5",
"signature_version": "v1",
"signature_type": "Function"
}
]