VDB
CVE-2023-49528
CVE-2023-49528
PUBLISHED
Es besteht eine Schwachstelle in ffmpeg. Dieser Fehler besteht aufgrund eines Buffer Overflow bei der Verwendung des "Dialoguenhance"-Filters. Ein lokaler Angreifer kann diese Schwachstelle ausnutzen, um beliebigen Code auszuführen oder einen Denial-of-Service-Zustand zu verursachen.
EPSS 0.03% · 7.5th percentile
Risk Scores
EPSS Score
0.03%
7.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu | Ubuntu Linux | |
| Fedora | Fedora Linux | |
| Open Source | Open Source ffmpeg n6.1-3-g466799d4f5 |
Exploit Intelligence
- CIRCL seen: CVE-2023-49528 (circl-sighting)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN/ (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY/ (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT/ (circl)
- https://trac.ffmpeg.org/ticket/10691 (circl)
- FEDORA-2024-92780a83f9 (circl)
- FEDORA-2024-55e7e839f1 (circl)
- FEDORA-2024-3a548f46a8 (circl)
Timeline
- Apr 11, 2024 CVE Published
- Apr 12, 2024 EPSS Score
- May 7, 2024 EPSS Score
- Jun 1, 2024 EPSS Score
- Jun 27, 2024 EPSS Score
- Jul 21, 2024 CVE Updated
- Jul 22, 2024 EPSS Score
- Aug 16, 2024 EPSS Score
- Sep 10, 2024 EPSS Score
- Oct 5, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 30, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0856.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0856 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-49528 advisory
- https://trac.ffmpeg.org/ticket/10691 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-0c24da3136 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-808f3961ef advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-4edaf658b7 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-f93392509c advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-ac000e6379 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-f74fbce604 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-92780a83f9 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-e94a7220f2 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-df7e365b4a advisory
- https://ubuntu.com/security/notices/USN-6803-1 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-810afc5c2e advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-4d2c8e6f85 advisory