« List of all CVEs

CVE-2023-6602

Ffmpeg: improper handling of input format in tty demuxer of ffmpeg

Published: 12/31/2024 Last updated: 11/3/2025 Reserved: 12/8/2023

A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 5.3 Medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Opam packages affected (3)

conf-ffmpeg ffmpeg opus

Products affected (2)

Product Vendor Version
QCA9992
MDM9650

References (6)