First published: Wed Dec 14 2022(Updated: )
[Suggested description] An issue was discovered in the FFmpeg through 3.0. vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause the null pointer dereference. ------------------------------------------ [VulnerabilityType Other] NULL Pointer Dereference ------------------------------------------ [Vendor of Product] the development group ------------------------------------------ [Affected Product Code Base] FFmpeg - 3.0 ------------------------------------------ [Reference] <a href="https://github.com/FFmpeg/FFmpeg/commit/656cb0450aeb73b25d7d26980af342b37ac4c568">https://github.com/FFmpeg/FFmpeg/commit/656cb0450aeb73b25d7d26980af342b37ac4c568</a> ------------------------------------------ [Discoverer] Jiasheng Jiang
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/FFmpeg | <5.1 | 5.1 |
debian/ffmpeg | <=7:4.1.9-0+deb10u1 | 7:4.1.11-0+deb10u1 7:4.3.6-0+deb11u1 7:5.1.3-1 7:6.0-7 |
FFmpeg FFmpeg | <5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3109 is a vulnerability in the FFmpeg package that can cause a null pointer dereference, impacting availability.
CVE-2022-3109 can lead to a null pointer dereference, which can result in crashes or system instability.
CVE-2022-3109 has a severity rating of 7.5, indicating a high severity.
To fix CVE-2022-3109, update the FFmpeg package to version 5.1 or higher.
You can find more information about CVE-2022-3109 in the references provided: [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2153551), [GitHub](https://github.com/FFmpeg/FFmpeg/commit/656cb0450aeb73b25d7d26980af342b37ac4c568), [Debian mailing list](https://lists.debian.org/debian-lts-announce/2023/06/msg00016.html).