CVE-2024-35367

Name
CVE-2024-35367
Description
FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://github.com/ffmpeg/ffmpeg/commit/09e6840cf7a3ee07a73c3ae88a020bf27ca1a667
https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavcodec/ppc/vp8dsp_altivec.c#L53
https://gist.github.com/1047524396/9754a44845578358f6a403447c458ca4
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/02/msg00000.html

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ffmpeg edge-community 7.1.1-r0 Achill Gilgenast <achill@achill.org> fixed
ffmpeg 3.20-community 6.1.1-r8 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable