cve/2025/CVE-2025-57615.md
2025-09-29 21:09:30 +02:00

864 B

CVE-2025-57615

Description

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer overflow vulnerability in the Vector::new constructor function allows an attacker to cause a denial of service via a null pointer dereference. The vulnerability stems from an unchecked cast of a usize parameter to c_int, which can result in a negative value being passed to the underlying C function sws_allocVec().

POC

Reference

No PoCs from references.

Github