CVE-2024-31585: Medium severity FFmpeg FFmpeg vulnerability
Published Apr 17, 2024
·Updated
FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability in libavfilter/avfshowspectrum.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Affected Software
6 affected componentsFixes available
ubuntu/ffmpeg<7:6.0-6ubuntu1.1
7:6.0-6ubuntu1.1
debian/ffmpeg<=7:6.1.1-4, <=7:6.1.1-5
7:4.3.6-0+deb11u17:4.3.7-0+deb11u17:5.1.5-0+deb12u1
FFmpeg FFmpeg>=5.1<7.0
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Fedoraproject Fedora=40
Remediation
Event History
Apr 17, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
Description
Data Sourced
via NVD·07:15 PM
RemedySeverityWeaknessAffected Software
Jun 27, 2024
Data Sourced
via Launchpad·07:04 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-31585?
CVE-2024-31585 is categorized as a Denial of Service (DoS) vulnerability.
2
How do I fix CVE-2024-31585?
To address CVE-2024-31585, update FFmpeg to versions 7:6.0-6ubuntu1.1 or greater on Ubuntu, or to 7:4.3.6-0+deb11u1, 7:4.3.7-0+deb11u1, or 7:5.1.5-0+deb12u1 on Debian.
3
Which FFmpeg versions are affected by CVE-2024-31585?
CVE-2024-31585 affects FFmpeg versions from n5.1 to n6.1.
4
What type of vulnerability is CVE-2024-31585?
CVE-2024-31585 is identified as an Off-by-one Error vulnerability.
5
What can attackers do with CVE-2024-31585?
Attackers can exploit CVE-2024-31585 to induce a Denial of Service (DoS) condition through crafted input.