CVE-2025-1373

Name
CVE-2025-1373
Description
A vulnerability was found in FFmpeg up to 7.1. It has been rated as problematic. Affected by this issue is the function mov_read_trak of the file libavformat/mov.c of the component MOV Parser. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The patch is identified as 43be8d07281caca2e88bfd8ee2333633e1fb1a13. It is recommended to apply a patch to fix this issue.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
product https://ffmpeg.org/
patch https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/43be8d07281caca2e88bfd8ee2333633e1fb1a13
exploit https://trac.ffmpeg.org/attachment/ticket/11460/poc
issue-tracking https://trac.ffmpeg.org/ticket/11460
signature https://vuldb.com/?ctiid.295982
vdb-entry https://vuldb.com/?id.295982
third-party-advisory https://vuldb.com/?submit.496930

Match rules

CPE URI Source package Min version Max version
ffmpeg == 7.0 == 7.0
ffmpeg == 7.1 == 7.1
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* ffmpeg >= None <= 7.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ffmpeg edge-community 6.1.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 6.1.2-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg 3.22-community 6.1.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg 3.22-community 6.1.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ffmpeg edge-community 8.0-r0 Achill Gilgenast <achill@achill.org> fixed