Bugzilla – Bug 1216695
VUL-0: CVE-2023-46407: ffmpeg,ffmpeg-4: out of bounds read via the dist->alphabet_size variable in the read_vlc_prefix() function.
Last modified: 2023-10-30 08:42:05 UTC
FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the read_vlc_prefix() function. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-46407
This is in the jpegxl parser recently added in the upstream repository and never included in any of ffmpeg releases. Since we don't ship it anywhere, closing this bug.