CVE-2024-35368: Double Free
Published Nov 29, 2024
·Updated
FFmpeg n7.0 is affected by a Double Free via the rkmppretrieveframe function within libavcodec/rkmppdec.c.
Affected Software
2 affected components
FFmpeg FFmpeg
FFmpeg FFmpeg=7.0
Remediation
Event History
Nov 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35368?
CVE-2024-35368 is classified as a high-severity vulnerability due to the potential for exploitation through a double free condition.
2
How do I fix CVE-2024-35368?
To fix CVE-2024-35368, you should update to the latest version of FFmpeg that patches the vulnerability.
3
What impact does CVE-2024-35368 have on affected systems?
CVE-2024-35368 can lead to application crashes or potentially allow for arbitrary code execution, compromising system security.
4
Which versions of FFmpeg are affected by CVE-2024-35368?
FFmpeg version 7.0 is affected by CVE-2024-35368; earlier versions may also be vulnerable.
5
Where can I find more information about CVE-2024-35368?
Detailed information about CVE-2024-35368 can be found in the FFmpeg GitHub repository and associated commit logs.