CVE-2025-1594

A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
VulDBCNA
6.3 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
ffmpegffmpeg
𝑥
≤ 7.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libav
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
trusty
not-affected
ffmpeg
plucky
Fixed 7:7.1.1-1ubuntu1.2
released
oracular
ignored
noble
Fixed 7:6.1.1-3ubuntu5+esm4
released
jammy
Fixed 7:4.4.2-0ubuntu0.22.04.1+esm8
released
focal
Fixed 7:4.2.7-0ubuntu0.1+esm9
released
bionic
Fixed 7:3.4.11-0ubuntu0.1+esm9
released
xenial
Fixed 7:2.8.17-0ubuntu0.1+esm11
released