CVE-2022-1475: Integer Overflow
An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729parse() in llibavcodec/g729parser.c when processing a specially crafted file.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-1475?
CVE-2022-1475 is an integer overflow vulnerability found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729_parse() in llibavcodec/g729_parser.c when processing a specially crafted file.
What software is affected by CVE-2022-1475?
FFmpeg versions before 4.4.2 and before 5.0.1 are affected by CVE-2022-1475.
How severe is CVE-2022-1475?
CVE-2022-1475 has a severity level of low.
How do I fix CVE-2022-1475 on Ubuntu?
To fix CVE-2022-1475 on Ubuntu, update the ffmpeg package to version 7:4.4.2-1, 7:4.4.2-0ubuntu0.21.10.1, or 7:4.4.2-0ubuntu0.22.04.1 depending on your Ubuntu version.
How do I fix CVE-2022-1475 on Debian?
To fix CVE-2022-1475 on Debian, update the ffmpeg package to version 7:4.1.9-0+deb10u1, 7:4.1.11-0+deb10u1, 7:4.3.6-0+deb11u1, 7:5.1.3-1, or 7:6.0-7 depending on your Debian version.