CVE-2025-1594

EUVD-2025-4406
A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
VulDBCNA
6.3 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
Affected Products (NVD)
VendorProductVersion
ffmpegffmpeg
𝑥
≤ 7.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libav
focal
dne
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
not-affected
ffmpeg
bionic
Fixed 7:3.4.11-0ubuntu0.1+esm9
released
focal
Fixed 7:4.2.7-0ubuntu0.1+esm9
released
jammy
Fixed 7:4.4.2-0ubuntu0.22.04.1+esm8
released
noble
Fixed 7:6.1.1-3ubuntu5+esm4
released
oracular
ignored
plucky
Fixed 7:7.1.1-1ubuntu1.2
released
questing
Fixed 7:7.1.1-1ubuntu4
released
xenial
Fixed 7:2.8.17-0ubuntu0.1+esm11
released