2024-12-03 17:04:12 +00:00

68 lines
2.2 KiB
JSON

{
"id": "CVE-2024-36615",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-11-29T19:15:07.703",
"lastModified": "2024-12-03T16:15:22.197",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread."
},
{
"lang": "es",
"value": "FFmpeg n7.0 tiene una vulnerabilidad de condici\u00f3n ejecuci\u00f3n en el decodificador VP9. Esto podr\u00eda provocar una ejecuci\u00f3n de datos si se exportaran par\u00e1metros de codificaci\u00f3n de video, ya que los datos secundarios se adjuntar\u00edan en el hilo del decodificador mientras se le\u00edan en el hilo de salida."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.2,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-362"
}
]
}
],
"references": [
{
"url": "https://gist.github.com/1047524396/c44e5eaafa8f408eea0c9411205990fb",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/FFmpeg/FFmpeg/blob/n7.0/libavcodec/vp9.c#L1738",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/ffmpeg/ffmpeg/commit/0ba058579f332b3060d8470a04ddd3fbf305be61",
"source": "cve@mitre.org"
}
]
}