A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.2 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-273651.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  Debian DLA | 
                DLA-3928-1 | ffmpeg security update | 
  Debian DSA | 
                DSA-5748-1 | ffmpeg security update | 
  EUVD | 
                EUVD-2024-48054 | A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.2 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-273651. | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Mon, 03 Nov 2025 23:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Wed, 04 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Ffmpeg
         Ffmpeg ffmpeg  | 
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Ffmpeg
         Ffmpeg ffmpeg  | 
Thu, 08 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-11-03T22:32:48.492Z
Reserved: 2024-07-23T19:38:00.873Z
Link: CVE-2024-7055
Updated: 2024-08-08T15:41:33.906Z
Status : Modified
Published: 2024-08-06T06:15:36.107
Modified: 2025-11-03T23:17:31.483
Link: CVE-2024-7055
No data.
                        OpenCVE Enrichment
                    No data.
 Debian DLA
 Debian DSA
 EUVD