CVE-2023-50010: Buffer Overflow
Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the setencoderid function in /fftools/ffmpegenc.c component.
Other sources
FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ffgradfunblurlinemovdqasse2, as demonstrated by a call to the setencoderid function in /fftools/ffmpegenc.c component.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50010?
CVE-2023-50010 is rated as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2023-50010?
To remediate CVE-2023-50010, users should upgrade to the patched versions of FFmpeg as specified for their respective operating systems.
Which versions of FFmpeg are affected by CVE-2023-50010?
CVE-2023-50010 affects FFmpeg versions prior to 7:3.4.11-0ubuntu0.1+, 7:4.2.7-0ubuntu0.1+, 7:4.4.2-0ubuntu0.22.04.1+, and 7:6.0-6ubuntu1.1, among others.
Is CVE-2023-50010 a local or remote vulnerability?
CVE-2023-50010 is classified as a local vulnerability, meaning it can be exploited by a local attacker.
What component of FFmpeg is impacted by CVE-2023-50010?
CVE-2023-50010 specifically impacts the set_encoder_id function in the /fftools/ffmpeg_enc.c component of FFmpeg.