CVE-2025-1373

Name
CVE-2025-1373
Description
A vulnerability was found in FFmpeg up to 7.1. It has been rated as problematic. Affected by this issue is the function mov_read_trak of the file libavformat/mov.c of the component MOV Parser. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The patch is identified as 43be8d07281caca2e88bfd8ee2333633e1fb1a13. It is recommended to apply a patch to fix this issue.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
product https://ffmpeg.org/
patch https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/43be8d07281caca2e88bfd8ee2333633e1fb1a13
exploit https://trac.ffmpeg.org/attachment/ticket/11460/poc
issue-tracking https://trac.ffmpeg.org/ticket/11460
signature https://vuldb.com/?ctiid.295982
vdb-entry https://vuldb.com/?id.295982
third-party-advisory https://vuldb.com/?submit.496930

Match rules

CPE URI Source package Min version Max version
ffmpeg == 7.0 == 7.0
ffmpeg == 7.1 == 7.1
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* ffmpeg >= None <= 7.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ffmpeg edge-community 8.0-r0 Achill Gilgenast <achill@achill.org> fixed
ffmpeg edge-community 6.1.2-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.1-r10 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.1-r9 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.1-r8 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.1-r7 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.1-r6 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.1-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.1-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.1-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.1-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r27 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r26 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r25 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r24 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r23 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r22 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r21 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r20 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r19 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r18 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r17 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r16 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r15 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r14 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r13 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r12 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r10 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r9 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r8 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r7 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r6 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1.2-r9 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1.2-r8 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1.2-r7 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1.2-r6 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1.2-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1.2-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1.2-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.0.1-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.0.1-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.0.1-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.0.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.0.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.0-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.0-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.0-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 5.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 4.4.1-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 4.4.1-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 4.4.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 4.4.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 4.4-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 4.4-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 4.4-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 4.4-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 4.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 4.3.2-r0 None possibly vulnerable
ffmpeg edge-community 4.3.1-r0 None possibly vulnerable
ffmpeg edge-community 4.3-r0 None possibly vulnerable
ffmpeg edge-community 4.2.1-r0 None possibly vulnerable
ffmpeg edge-community 4.2-r0 None possibly vulnerable
ffmpeg edge-community 4.1.4-r0 None possibly vulnerable
ffmpeg edge-community 4.1.3-r0 None possibly vulnerable
ffmpeg edge-community 4.1.1-r0 None possibly vulnerable
ffmpeg edge-community 4.1-r0 None possibly vulnerable
ffmpeg edge-community 4.0.2-r0 None possibly vulnerable
ffmpeg edge-community 4.0.1-r0 None possibly vulnerable
ffmpeg edge-community 4.0.0-r0 None possibly vulnerable
ffmpeg edge-community 3.4.4-r0 None possibly vulnerable
ffmpeg edge-community 3.4.3-r0 None possibly vulnerable
ffmpeg edge-community 3.3.4-r0 None possibly vulnerable
ffmpeg 3.22-community 6.1.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg 3.22-community 6.1.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg 3.22-community 6.1-r0 None possibly vulnerable
ffmpeg 3.22-community 6.0.1-r0 None possibly vulnerable
ffmpeg 3.22-community 6.0-r0 None possibly vulnerable
ffmpeg 3.22-community 5.1-r1 None possibly vulnerable
ffmpeg 3.22-community 4.4.1-r0 None possibly vulnerable
ffmpeg 3.22-community 4.4-r1 None possibly vulnerable
ffmpeg 3.22-community 4.4-r0 None possibly vulnerable
ffmpeg 3.22-community 4.3.2-r0 None possibly vulnerable
ffmpeg 3.22-community 4.3.1-r0 None possibly vulnerable
ffmpeg 3.22-community 4.3-r0 None possibly vulnerable
ffmpeg 3.22-community 4.2.1-r0 None possibly vulnerable
ffmpeg 3.22-community 4.2-r0 None possibly vulnerable
ffmpeg 3.22-community 4.1.4-r0 None possibly vulnerable
ffmpeg 3.22-community 4.1.3-r0 None possibly vulnerable
ffmpeg 3.22-community 4.1.1-r0 None possibly vulnerable
ffmpeg 3.22-community 4.1-r0 None possibly vulnerable
ffmpeg 3.22-community 4.0.2-r0 None possibly vulnerable
ffmpeg 3.22-community 4.0.1-r0 None possibly vulnerable
ffmpeg 3.22-community 4.0.0-r0 None possibly vulnerable
ffmpeg 3.22-community 3.4.4-r0 None possibly vulnerable
ffmpeg 3.22-community 3.4.3-r0 None possibly vulnerable
ffmpeg 3.22-community 3.3.4-r0 None possibly vulnerable