CVE-2024-36617: Integer Overflow
Published Nov 29, 2024
·Updated
FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
Affected Software
6 affected componentsFixes available
FFmpeg FFmpeg<3.4.14
FFmpeg FFmpeg>=4.0<4.2.9
FFmpeg FFmpeg>=4.3<4.3.7
FFmpeg FFmpeg>=4.4<4.4.5
FFmpeg FFmpeg>=5.0<6.1.2
debian/ffmpeg
7:4.3.7-0+deb11u17:4.3.9-0+deb11u27:5.1.8-0+deb12u17:5.1.9-0+deb12u17:7.1.3-0+deb13u17:7.1.4-0+deb13u17:8.1.1-3
Remediation
Event History
Nov 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 28, 2026
Data Sourced
via Debian·01:17 PM
DescriptionAffected Software
Data Sourced
via Launchpad·01:17 PM
Description
May 29, 2026
Data Sourced
via Ubuntu·01:16 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-36617?
CVE-2024-36617 is classified as a high-severity vulnerability due to the potential for exploitation via integer overflow.
2
How do I fix CVE-2024-36617?
To remediate CVE-2024-36617, upgrade your FFmpeg installation to version 7:5.1.6-0+deb12u1 or 7:7.1-3.
3
What software is affected by CVE-2024-36617?
CVE-2024-36617 affects FFmpeg versions prior to 7:5.1.6-0+deb12u1 and 7:7.1-3.
4
What vulnerabilities does CVE-2024-36617 introduce?
CVE-2024-36617 introduces an integer overflow vulnerability in the FFmpeg CAF decoder, which could lead to potential code execution.
5
When was CVE-2024-36617 last updated?
CVE-2024-36617 was last updated on 8 January 2025.