CVE-2024-35365

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 3, 2025
CWE ID 415

Summary

CVE-2024-35365 is a newly identified vulnerability affecting FFmpeg version n6.1.1. This issue involves a double-free error in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function. The double-free vulnerability refers to the improper release of memory, leading to potential memory corruption. An attacker could exploit this flaw to execute arbitrary code, leading to serious security implications. Upgrading to a patched version of FFmpeg is highly recommended to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share