Bug 1219283 (CVE-2024-22862)

Summary: VUL-0: CVE-2024-22862: ffmpeg,ffmpeg-4: Integer overflow vulnerability in FFmpeg via the JJPEG XL Parser.
Product: [Novell Products] SUSE Security Incidents Reporter: SMASH SMASH <smash_bz>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P5 - None CC: andrea.mattiazzo
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/392370/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-22862:6.3:(AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Comment 1 Andrea Mattiazzo 2024-01-29 11:19:54 UTC
Closed because all code stream are not affected. JPEG XL parse added via https://github.com/FFmpeg/FFmpeg/commit/0c0dd23fe1102313742092c4760596971755814e on version 6.1