CVE-2025-0518: Unchecked sscanf return value which leads to memory data leak
Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/afpan.C .
This issue affects FFmpeg: 7.1.
Issue was fixed: https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a
https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a This issue was discovered by: Simcha Kosman
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0518?
CVE-2025-0518 has been classified as a medium severity vulnerability.
How does CVE-2025-0518 affect FFmpeg?
CVE-2025-0518 allows for an out-of-bounds read which can expose sensitive constants within the FFmpeg executable.
How can I remediate CVE-2025-0518 in FFmpeg?
To fix CVE-2025-0518, update to FFmpeg version 7.1 or later where the vulnerability has been addressed.
What types of systems are affected by CVE-2025-0518?
CVE-2025-0518 affects all systems running FFmpeg version 7.1.
What is the nature of the vulnerability in CVE-2025-0518?
CVE-2025-0518 is an unchecked return value vulnerability leading to an out-of-bounds read.