First published: Thu Jan 16 2025(Updated: )
Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C . This issue affects FFmpeg: 7.1. Issue was fixed: https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a This issue was discovered by: Simcha Kosman
Credit: 96148269-fe82-4198-b1bf-3a73ce8bc92e
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0518 has been classified as a medium severity vulnerability.
CVE-2025-0518 allows for an out-of-bounds read which can expose sensitive constants within the FFmpeg executable.
To fix CVE-2025-0518, update to FFmpeg version 7.1 or later where the vulnerability has been addressed.
CVE-2025-0518 affects all systems running FFmpeg version 7.1.
CVE-2025-0518 is an unchecked return value vulnerability leading to an out-of-bounds read.