CVE-2023-46407: Ffmpeg

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the read_vlc_prefix() function.

Affected products

  • Ffmpeg Ffmpeg: version 6.1 only

Published 2023-10-27. Last modified 2026-06-17.