An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer overflow vulnerability in the Vector::new constructor function allows an attacker to cause a denial of service via a null pointer dereference. The vulnerability stems from an unchecked cast of a usize parameter to c_int, which can result in a negative value being passed to the underlying C function sws_allocVec().
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/meh/rust-ffmpeg/issues/192 |
![]() ![]() |
History
Tue, 02 Sep 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer overflow vulnerability in the Vector::new constructor function allows an attacker to cause a denial of service via a null pointer dereference. The vulnerability stems from an unchecked cast of a usize parameter to c_int, which can result in a negative value being passed to the underlying C function sws_allocVec(). | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-02T15:58:53.484Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-57615

No data.

Status : Received
Published: 2025-09-02T16:15:40.443
Modified: 2025-09-02T16:15:40.443
Link: CVE-2025-57615

No data.

No data.