Bug 1223253 (CVE-2023-50007) - VUL-0: CVE-2023-50007: ffmpeg,ffmpeg-4: arbitrary code execution via theav_samples_set_silence function in thelibavutil/samplefmt.c
Summary: VUL-0: CVE-2023-50007: ffmpeg,ffmpeg-4: arbitrary code execution via theav_sa...
Status: RESOLVED FIXED
Alias: CVE-2023-50007
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/402760/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-50007:8.8:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-04-22 12:32 UTC by SMASH SMASH
Modified: 2024-05-17 17:41 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-04-22 12:32:26 UTC
Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via theav_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-50007
https://www.cve.org/CVERecord?id=CVE-2023-50007
https://github.com/FFmpeg/FFmpeg/commit/b1942734c7cbcdc9034034373abcc9ecb9644c47
https://trac.ffmpeg.org/ticket/10700
https://bugzilla.redhat.com/show_bug.cgi?id=2276128
Comment 3 Camila Camargo de Matos 2024-04-23 10:39:38 UTC
Considering that the fixing commit for this issue is commit b1942734 [0], it would seem like no FFmpeg version before version 5.0 can be fixed, as file 'libavfilter/af_afwtdn.c' was only added to the FFmpeg code at this version.

Changes from commit 6846d48f [1] are the ones that add the afwtdn filter functionality. If the root cause of the vulnerability is indeed located in this part of the code only, then FFmpeg before 5.0 is not vulnerable to CVE-2023-50007. 

Considering that the upstream ticket [2] has been closed and no other commits are referenced by the only provided fixing commit in the CVE references, it is possible that there will be no other fixes other than the one applied to 'libavfilter/af_afwtdn.c'.

[0] https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/b1942734c7cbcdc9034034373abcc9ecb9644c47
[1] https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/6846d48fa64d077c0b5e7786d4a9d49a3d81025d
[2] https://trac.ffmpeg.org/ticket/10700
Comment 4 OBSbugzilla Bot 2024-04-25 09:35:03 UTC
This is an autogenerated message for OBS integration:
This bug (1223253) was mentioned in
https://build.opensuse.org/request/show/1170119 Factory / ffmpeg-6
Comment 5 OBSbugzilla Bot 2024-04-25 23:05:05 UTC
This is an autogenerated message for OBS integration:
This bug (1223253) was mentioned in
https://build.opensuse.org/request/show/1170214 Factory / ffmpeg-5