VDB
BDU%3A2024-05029
BDU%3A2024-05029
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Уязвимость компонента image_copy_plane (libavutil/imgutils.c) мультимедийной библиотеки FFmpeg, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
6.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical Ltd., Сообщество свободного программного обеспечения, ООО «РусБИТех-Астра», Fedora Project, FFmpeg team | Ubuntu, Debian GNU/Linux, Astra Linux Special Edition (запись в едином реестре российских программ №369), Fedora, Astra Linux Common Edition (запись в едином реестре российских программ №4433), FFmpeg | |
| ffmpeg | ffmpeg | - |
| n/a | n/a | n/a |
Timeline
- Apr 19, 2024 CVE Published
- Jan 20, 2026 CVE Updated
- Mar 19, 2026 Distribution Patch
- May 27, 2026 Security Advisory
References
- https://github.com/FFmpeg/FFmpeg/commit/0ecc1f0e48930723d7a467761b66850811c23e62 advisory
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2024-1031SE47 advisory
- https://safe-surf.ru/upload/VULN-new/VULN.2024-05-13.1.pdf url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2024-0830SE17 url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20251225SE16 url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/ url
- https://ubuntu.com/security/notices/USN-6803-1 advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/ advisory
- FEDORA-2024-92780a83f9 vendor-advisory
- https://ffmpeg.org/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/ url
- https://security-tracker.debian.org/tracker/CVE-2023-51793 url
- https://trac.ffmpeg.org/ticket/10743 advisory