CVE-2024-36616: Integer Overflow
Published Nov 29, 2024
·Updated
An integer overflow in the component /libavformat/westwoodvqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file.
Affected Software
2 affected components
FFmpeg FFmpeg=6.1.1
FFmpeg FFmpeg=6.1.1
Remediation
Event History
Nov 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36616?
CVE-2024-36616 is classified as a denial of service vulnerability.
2
How do I fix CVE-2024-36616?
To fix CVE-2024-36616, upgrade to a patched version of FFmpeg beyond 6.1.1.
3
What causes CVE-2024-36616?
CVE-2024-36616 is caused by an integer overflow in the westwood_vqa.c component of FFmpeg.
4
Which versions of FFmpeg are affected by CVE-2024-36616?
Only FFmpeg version 6.1.1 is reported as affected by CVE-2024-36616.
5
Can CVE-2024-36616 be exploited remotely?
Yes, CVE-2024-36616 can be exploited remotely through a crafted VQA file.