Description
A vulnerability was found in FFmpeg 2.0. It has been declared as problematic. Affected by this vulnerability is the function decode_frame of the file libavcodec/ansi.c. The manipulation leads to integer coercion error. The attack can be launched remotely. It is recommended to apply a patch to fix this issue.
References (2)
Core 2
Core References
Patch x_refsource_misc
http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=d42ec8433c687fcbccefa51a7716d81920218e4f
Third Party Advisory, VDB Entry x_refsource_misc
https://vuldb.com/?id.12391
Scores
CVSS v3
5.3
EPSS
0.0055
EPSS Percentile
41.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-681
CWE-192
Status
published
Products (1)
ffmpeg/ffmpeg
2.0
Published
Jun 18, 2022
Tracked Since
Feb 18, 2026