CVE-2023-50008

Name
CVE-2023-50008
Description
FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9 component.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/FFmpeg/FFmpeg/commit/5f87a68cf70dafeab2fb89b42e41a4c29053b89b
cve@mitre.org https://trac.ffmpeg.org/ticket/10701
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/
cve@mitre.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/
cve@mitre.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/
cve@mitre.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* ffmpeg >= 6.1 < 7.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ffmpeg edge-community 7.1.1-r0 Achill Gilgenast <achill@achill.org> fixed
ffmpeg edge-community 6.1.2-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg 3.22-community 6.1.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg 3.22-community 6.1.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable