Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-7055


A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.2 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-273651.


Published

2024-08-06T06:15:36.107

Last Modified

2025-06-03T17:20:06.493

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-122
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ffmpeg ffmpeg < 4.3.8 Yes
Application ffmpeg ffmpeg < 4.4.5 Yes
Application ffmpeg ffmpeg < 5.1.6 Yes
Application ffmpeg ffmpeg < 6.1.2 Yes
Application ffmpeg ffmpeg < 7.0.2 Yes

References