| Package | ffmpeg |
|---|---|
| Version | 7:3.2.19-0+deb9u8 (stretch) |
| Related CVEs | CVE-2020-22027 CVE-2023-6603 CVE-2025-1594 CVE-2025-7700 CVE-2025-9951 CVE-2025-10256 |
Several issues have been found in ffmpeg, a library and tools for transcoding, streaming and playing of multimedia files.
- CVE-2020-22027
-
A heap-based Buffer Overflow vulnerability exits in FFmpeg 4.2 in deflate16 at libavfilter/vf_neighbor.c, which might lead to memory corruption and other potential consequences.
- CVE-2023-6603
-
A flaw was found in FFmpeg’s HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization.
- CVE-2025-1594
-
A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
- CVE-2025-7700
-
A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.
- CVE-2025-9951
-
A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
- CVE-2025-10256
-
A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.
For Debian 9 stretch, these problems have been fixed in version 7:3.2.19-0+deb9u8.
We recommend that you upgrade your ffmpeg packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.