2024-12-08 03:06:42 +00:00

68 lines
2.5 KiB
JSON

{
"id": "CVE-2024-35369",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-11-29T17:15:07.707",
"lastModified": "2024-11-29T18:15:06.983",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process."
},
{
"lang": "es",
"value": "En la versi\u00f3n n6.1.1 de FFmpeg, espec\u00edficamente dentro del m\u00f3dulo avcodec/speexdec.c, existe una vulnerabilidad de seguridad potencial debido a una validaci\u00f3n insuficiente de ciertos par\u00e1metros al analizar los datos adicionales del c\u00f3dec Speex. Esta vulnerabilidad podr\u00eda generar condiciones de desbordamiento de n\u00fameros enteros, lo que podr\u00eda generar un comportamiento indefinido o fallos durante el proceso de decodificaci\u00f3n."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-190"
}
]
}
],
"references": [
{
"url": "https://gist.github.com/1047524396/455093807666f2e351d674750c8cd0b8",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavcodec/speexdec.c#L1423",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/ffmpeg/ffmpeg/commit/0895ef0d6d6406ee6cd158fc4d47d80f201b8e9c",
"source": "cve@mitre.org"
}
]
}