CVE-2023-46407: Ffmpeg
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the read_vlc_prefix() function.
Affected products
- Ffmpeg Ffmpeg: version 6.1 only
Published 2023-10-27. Last modified 2026-06-17.