First published: Fri Jul 28 2023(Updated: )
## Withdrawn This advisory has been withdrawn because it has been found to be disputed. Please see the issue [here](https://github.com/bramp/ffmpeg-cli-wrapper/issues/291) for more information. ## Original Despcription FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>. This vulnerability is exploited via passing an unchecked argument.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bramp Ffmpeg-cli-wrapper | <=0.7.0 | |
maven/net.bramp.ffmpeg:ffmpeg | <=0.7.0 | |
FFmpeg FFmpeg | <=0.7 | |
<=0.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-39018 is critical, with a severity value of 9.8.
The affected software of CVE-2023-39018 includes FFmpeg versions up to and including 0.7.0 and Bramp Ffmpeg-cli-wrapper version up to and including 0.7.0.
CVE-2023-39018 can be exploited by passing an unchecked argument, allowing code injection in the component net.bramp.ffmpeg.FFmpeg.<constructor>.
At the moment, there doesn't seem to be a fix available for CVE-2023-39018. It is recommended to update to the latest version of FFmpeg and Bramp Ffmpeg-cli-wrapper when a fix is released.
You can find more information about CVE-2023-39018 on the GitHub issue page: https://github.com/bramp/ffmpeg-cli-wrapper/issues/291.