CVE Vulnerabilities

CVE-2024-35365

Double Free

Published: Jan 03, 2025 | Modified: Jan 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
4.6 MODERATE
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM

FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Ffmpeg Ubuntu esm-apps/bionic *
Ffmpeg Ubuntu esm-apps/focal *
Ffmpeg Ubuntu esm-apps/jammy *
Ffmpeg Ubuntu esm-apps/noble *
Ffmpeg Ubuntu esm-apps/xenial *
Ffmpeg Ubuntu focal *
Ffmpeg Ubuntu jammy *
Ffmpeg Ubuntu noble *
Ffmpeg Ubuntu upstream *

Potential Mitigations

References