VDB
BDU%3A2024-06374
BDU%3A2024-06374
PUBLISHED
CVSS 10 CRITICAL
Уязвимость функции fill_audiodata файла /libswresample/swresample.c мультимедийной библиотеки FFmpeg, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «РусБИТех-Астра», FFmpeg team, ООО «Открытая мобильная платформа» | Astra Linux Special Edition (запись в едином реестре российских программ №369), FFmpeg, ОС Аврора (запись в едином реестре российских программ №1543) |
Timeline
- Aug 21, 2024 CVE Published
- Sep 5, 2025 CVE Updated
References
- https://github.com/CookedMelon/ReportCVE/tree/main/FFmpeg/poc5 url
- https://github.com/CookedMelon/ReportCVE/tree/main/FFmpeg/poc6 url
- https://ffmpeg.org url
- https://vuldb.com/?id.273945 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2024-1031SE47 url
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-0114SE18MD url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0319SE17 url
- https://cve.omp.ru/bb27514 url
- https://ffmpeg.org/ advisory