
DescriptionFFMPEG version 4.1 contains a CWE-129: Improper Validation of Array Index vulnerability in libavcodec/cbs_av1.c that can result in Denial of service. This attack appears to be exploitable via specially crafted AV1 file has to be provided as input. This vulnerability appears to have been fixed in after commit b97a4b658814b2de8b9f2a3bce491c002d34de31.
Debian Bugs922066

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ffmpeg (PTS)buster7:4.1.9-0+deb10u1fixed
buster (security)7:4.1.11-0+deb10u1fixed
bullseye (security), bullseye7:4.3.6-0+deb11u1fixed
bookworm, bookworm (security)7:5.1.4-0+deb12u1fixed
sid, trixie7:6.1.1-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ffmpegsourcestretch(not affected)
libavsourcejessie(not affected)


[stretch] - ffmpeg <not-affected> (Vulnerable code not present)
[jessie] - libav <not-affected> (Vulnerable code not present)

