CVE-2024-35369

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
29/11/2024
Last modified:
03/06/2025

Description

In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ffmpeg:ffmpeg:6.1.1:*:*:*:*:*:*:*