Bug ID 1223215
Summary VUL-0: CVE-2023-49501: ffmpeg: buffer overflow via the config_eq_output function in libavfilter/asrc_afirsrc.c
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/402757/
OS Other
Status NEW
Severity Critical
Priority P5 - None
Component Other
Assignee jengelh@inai.de
Reporter smash_bz@suse.de
QA Contact security-team@suse.de
CC camila.matos@suse.com
Target Milestone ---
Found By Security Response Team
Blocker ---

Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local
attacker to execute arbitrary code via the config_eq_output function in the
libavfilter/asrc_afirsrc.c:495:30 component.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-49501
https://www.cve.org/CVERecord?id=CVE-2023-49501
https://github.com/FFmpeg/FFmpeg
https://trac.ffmpeg.org/ticket/10686
https://trac.ffmpeg.org/ticket/10686#no1
https://bugzilla.redhat.com/show_bug.cgi?id=2276114


You are receiving this mail because: