MGASA-2025-0306

Source
https://advisories.mageia.org/MGASA-2025-0306.html
Import Source
https://advisories.mageia.org/MGASA-2025-0306.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2025-0306
Related
Published
2025-11-21T19:56:16Z
Modified
2025-11-21T19:58:55.804588Z
Summary
Updated ffmpeg packages fix security vulnerabilities
Details

FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the avsamplessetsilence function in thelibavutil/samplefmt.c:260:9 component. (CVE-2023-50007) FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the avmalloc function in libavutil/mem.c:105:9 component. (CVE-2023-50008) Improper handling of input format in tty demuxer of ffmpeg. (CVE-2023-6602) Hls xbin demuxer dos amplification in ffmpeg. (CVE-2023-6604) Dash playlist ssrf vulnerability in ffmpeg. (CVE-2023-6605) FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the drawblockrectangle function of libavfilter/vfcodecview.c. This vulnerability allows attackers to cause undefined behavior or a Denial of Service (DoS) via crafted input. (CVE-2024-31582) FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dspaltivec.c, static const vecs8 hsubpelfiltersouter. (CVE-2024-35367) Heap-buffer-overflow write in FFmpeg MDASH resolvecontentpath. (CVE-2025-59728) Heap-buffer-overflow write in FFmpeg EXR dwa_uncompress. (CVE-2025-59731, CVE-2025-59732, CVE-2025-59733) Null pointer dereference in ffmpeg als decoder (libavcodec/alsdec.c). (CVE-2025-7700)

References
Credits

Affected packages

Mageia:9 / ffmpeg

Package

Name
ffmpeg
Purl
pkg:rpm/mageia/ffmpeg?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.1.7-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / ffmpeg

Package

Name
ffmpeg
Purl
pkg:rpm/mageia/ffmpeg?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.1.7-1.mga9.tainted

Ecosystem specific

{
    "section": "tainted"
}