CRITICAL🇵🇱 Wersja polska

CVE-2024-35367

CVSS 9.1v3.1pub. 2024-11-29upd. 2025-11-03

FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer

🤖 AI Analysis
How it works

The vulnerability is located in the file libavcodec/ppc/vp8dsp_altivec.c, specifically in the static array h_subpel_filters_outer containing subpixel filters for VP8 codecs. When processing an appropriately crafted video stream, data is read beyond the boundaries of the allocated buffer. The error results from improper array indexing handling in code optimized for the AltiVec SIMD unit.

Impact

An attacker can cause disclosure of process memory contents (confidentiality breach) or unstable operation and crashes (denial of service — DoS). The attack vector is network-based and does not require authentication or user interaction.

Mitigation & patch

Apply the patch available in the FFmpeg repository (commit 09e6840cf7a3ee07a73c3ae88a020bf27ca1a667) or update the package according to the distributor's recommendations (including Debian LTS — communication from February 2025). Update to a version containing the indicated fix according to the manufacturer's references.

Who is affected

FFmpeg version n6.1.1 running on PowerPC architecture with AltiVec support when processing VP8 video streams.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • Ffmpeg

    APP
    Ffmpeg
    6.1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2024-35368CRITICAL9.8PL ✓same product

Double Free w FFmpeg — podatność w dekoderze RKMPP (libavcodec)

CVE-2024-35366CRITICAL9.1PL ✓same product

FFmpeg: Integer Overflow w parse_options (sbgdec.c) — moduł libavformat

CVE-2024-31581CRITICAL9.8PL ✓same product

FFmpeg: nieprawidłowa walidacja indeksu tablicy w dekodowaniu H.266

CVE-2024-22862CRITICAL9.8PL ✓same product

Integer overflow w FFmpeg — RCE przez parser JPEG XL

CVE-2024-22860CRITICAL9.8PL ✓same product

Integer overflow w FFmpeg — RCE przez dekoder animacji JPEG XL