First published: Fri Nov 29 2024(Updated: )
An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | =6.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36616 is classified as a denial of service vulnerability.
To fix CVE-2024-36616, upgrade to a patched version of FFmpeg beyond 6.1.1.
CVE-2024-36616 is caused by an integer overflow in the westwood_vqa.c component of FFmpeg.
Only FFmpeg version 6.1.1 is reported as affected by CVE-2024-36616.
Yes, CVE-2024-36616 can be exploited remotely through a crafted VQA file.