Bugzilla – Bug 1219283
VUL-0: CVE-2024-22862: ffmpeg,ffmpeg-4: Integer overflow vulnerability in FFmpeg via the JJPEG XL Parser.
Last modified: 2024-01-29 11:19:54 UTC
Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-22862 https://www.cve.org/CVERecord?id=CVE-2024-22862 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=62113 https://bugzilla.redhat.com/show_bug.cgi?id=2260697 Patch: https://github.com/FFmpeg/FFmpeg/commit/ca09d8a0dcd82e3128e62463231296aaf63ae6f7
Closed because all code stream are not affected. JPEG XL parse added via https://github.com/FFmpeg/FFmpeg/commit/0c0dd23fe1102313742092c4760596971755814e on version 6.1