A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=2334337 |
|
History
Tue, 05 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 06 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 06 Jan 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 |
Mon, 06 Jan 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation. | |
| Title | Ffmpeg: hls xbin demuxer dos amplification in ffmpeg | |
| Weaknesses | CWE-99 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fedora
Published: 2025-01-06T16:41:42.345Z
Updated: 2025-01-06T17:06:30.694Z
Reserved: 2023-12-08T06:53:59.354Z
Link: CVE-2023-6604
Updated: 2025-01-06T17:06:25.115Z
Status : Analyzed
Published: 2025-01-06T17:15:14.413
Modified: 2025-08-05T18:05:55.853
Link: CVE-2023-6604
No data.