First published: Tue Aug 06 2024(Updated: )
A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.2 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-273651.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | <=7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7055 has been classified as a critical vulnerability.
CVE-2024-7055 allows for a heap-based buffer overflow that can be exploited remotely.
CVE-2024-7055 affects FFmpeg versions up to and including 7.0.1.
To mitigate CVE-2024-7055, upgrade to the latest version of FFmpeg that addresses this vulnerability.
More details on CVE-2024-7055 can be found on FFmpeg's official documentation and security advisories.