First published: Fri Dec 27 2024(Updated: )
A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | >=2.0<6.0 | |
FFmpeg | >=3.0<5.0 | |
FFmpeg | >=4.2<6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6604 is considered a medium severity vulnerability due to its potential to cause degraded performance or denial of service.
To fix CVE-2023-6604, you should upgrade to FFmpeg version 6.0 or higher, or to version 5.0 if using an affected version between 3.0 and 5.0.
CVE-2023-6604 affects FFmpeg versions between 2.0 and 6.0, including versions within the 3.0 to 5.0 range.
CVE-2023-6604 can lead to unexpected CPU load and increased storage consumption, potentially resulting in denial of service.
There is currently no indication that CVE-2023-6604 is being actively exploited in the wild.