FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
Link | Tags |
---|---|
https://trac.ffmpeg.org/ticket/9312 | patch vendor advisory exploit |
https://www.debian.org/security/2021/dsa-4990 | third party advisory vendor advisory |
https://www.debian.org/security/2021/dsa-4998 | third party advisory vendor advisory |
https://lists.debian.org/debian-lts-announce/2021/11/msg00012.html | third party advisory mailing list |
https://security.gentoo.org/glsa/202312-14 | vendor advisory |