« List of all CVEs

CVE-2023-6604

Ffmpeg: hls xbin demuxer dos amplification in ffmpeg

Published: 1/6/2025 Last updated: 11/3/2025 Reserved: 12/8/2023

A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.

CNA assigner: fedora (92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 5.3 Medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Opam packages affected (3)

conf-ffmpeg ffmpeg opus

Products affected (2)

Product Vendor Version
< 58d52743ae85d28c9335c6034d6ce350b8689951
X2000077

References (4)