libav DSS File Demuxer avconv.c main double free

CVE Details

Basic Information

Title libav DSS File Demuxer avconv.c main double free
Type cve
Published 2025-08-05T17:02:06.134Z
Modified 2025-08-05T17:02:06.134Z

Product Information

Vendor n/a
Product libav
Version 12.0

CVSS Information

Base Score 4.8 (MEDIUM)
Attack Vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A critical double free vulnerability in libav’s DSS File Demuxer component could allow local attackers to execute arbitrary code. However, this issue affects versions of libav that are no longer supported by the maintainer.
AI Severity Medium
AI Vendor FFmpeg
AI Product libav
AI Version 12.0, 12.1, 12.2, 12.3

Affected Products

  • n/a libav 12.0
  • n/a libav 12.1
  • n/a libav 12.2
  • n/a libav 12.3

Additional Information

CWE List CWE-415, CWE-119
Source VulDB

Description

A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the function main of the file /avtools/avconv.c of the component DSS File Demuxer. The manipulation leads to double free. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The bug was initially reported by the researcher to the wrong project. This vulnerability only affects products that are no longer supported by the maintainer.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.