CVE-2023-6603

EUVD-2023-58826
A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 43.95%
Affected Products (NVD)
VendorProductVersion
ffmpegffmpeg
2.0 ≤
𝑥
≤ 6.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ffmpeg
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
sid
vulnerable
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ffmpeg
bionic
Fixed 7:3.4.11-0ubuntu0.1+esm11
released
focal
Fixed 7:4.2.7-0ubuntu0.1+esm11
released
jammy
Fixed 7:4.4.2-0ubuntu0.22.04.1+esm10
released
noble
not-affected
oracular
ignored
plucky
ignored
questing
ignored
resolute
needed
xenial
Fixed 7:2.8.17-0ubuntu0.1+esm13
released
libav
focal
dne
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
resolute
dne
trusty
needs-triage