libav MPEG File Parser utils.c ff_seek_frame_binary null pointer dereference

CVE Details

Basic Information

Title libav MPEG File Parser utils.c ff_seek_frame_binary null pointer dereference
Type cve
Published 2025-08-05T17:32:05.219Z
Modified 2025-08-05T17:32:05.219Z

Product Information

Vendor n/a
Product libav
Version 12.0

CVSS Information

Base Score 4.8 (MEDIUM)
Attack Vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A null pointer dereference vulnerability in libav’s MPEG File Parser could allow an attacker to cause a denial of service via a malformed file.
AI Severity Medium
AI Vendor FFmpeg Community
AI Product libav
AI Version 12.0, 12.1, 12.2, 12.3

Affected Products

  • n/a libav 12.0
  • n/a libav 12.1
  • n/a libav 12.2
  • n/a libav 12.3

Additional Information

CWE List CWE-476, CWE-404
Source VulDB

Description

A vulnerability, which was classified as problematic, was found in libav up to 12.3. This affects the function ff_seek_frame_binary of the file /libavformat/utils.c of the component MPEG File Parser. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The bug was initially reported by the researcher to the wrong project. This vulnerability only affects products that are no longer supported by the maintainer.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.