CVE-2023-51796: Buffer Overflow
Published Apr 19, 2024
·Updated
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/freverse.c:269:26 in areverserequestframe.
Affected Software
18 affected componentsFixes available
ubuntu/ffmpeg<7:6.0-6ubuntu1.1
7:6.0-6ubuntu1.1
debian/ffmpeg<=7:6.1.1-4, <=7:6.1.1-5
7:4.3.6-0+deb11u17:4.3.7-0+deb11u17:5.1.5-0+deb12u1
FFmpeg FFmpeg=7.0
FFmpeg FFmpeg=7.0.1
FFmpeg FFmpeg=7.0.2
FFmpeg FFmpeg=7.0.3
FFmpeg FFmpeg=7.1
FFmpeg FFmpeg=7.1-dev
FFmpeg FFmpeg=7.1.1
FFmpeg FFmpeg=7.1.2
FFmpeg FFmpeg=7.1.3
FFmpeg FFmpeg=7.2-dev
FFmpeg FFmpeg=8.0
FFmpeg FFmpeg=8.0.1
FFmpeg FFmpeg=8.1-dev
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Fedoraproject Fedora=40
Event History
Apr 19, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
Affected Software
Jun 27, 2024
Data Sourced
via Launchpad·07:04 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-51796?
CVE-2023-51796 has a high severity rating due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2023-51796?
To fix CVE-2023-51796, update ffmpeg to version 7:6.0-6ubuntu1.1 for Ubuntu or to one of the specified versions for Debian.
3
Who is affected by CVE-2023-51796?
CVE-2023-51796 affects users of ffmpeg versions prior to 7:6.1.1-4 and 7:6.1.1-5 on Debian and specified Ubuntu versions.
4
What components are involved in CVE-2023-51796?
CVE-2023-51796 involves a buffer overflow vulnerability located in libavfilter/f_reverse.c within the ffmpeg library.
5
Can CVE-2023-51796 be exploited remotely?
CVE-2023-51796 is a local vulnerability, meaning exploitation requires local access to the system.