VDB
DEBIAN-CVE-2025-7700
DEBIAN-CVE-2025-7700
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | ffmpeg | 7:4.3.8-0+deb11u3, 7:4.3.2-0+deb11u2, 7:4.3.2-1 |
| Debian:14 | ffmpeg | 0, 7:7.1.1-1, 0 |
| Debian:13 | ffmpeg | 7.1.1-1, 0, 7:7.1.1-1 |
| Debian:12 | ffmpeg | 7:5.1.6-0+deb12u1, 0, 5.1.3-1 |
Exploit Intelligence
- owasp-suppressions.xml (github-poc)
Timeline
- Nov 7, 2025 CVE Published
- Apr 28, 2026 CVE Updated