CVE-2024-36617: Ffmpeg
Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.
FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
Affected products
- Ffmpeg Ffmpeg: before 3.4.14 (fixed in 3.4.14); from 4.0, before 4.2.9 (fixed in 4.2.9); from 4.3, before 4.3.7 (fixed in 4.3.7); from 4.4, before 4.4.5 (fixed in 4.4.5); from 5.0, before 6.1.2 (fixed in 6.1.2)
Published 2024-11-29. Last modified 2026-06-17.