Impact
An integer overflow in libswscale/utils.c allows an attacker to trigger a DoS by supplying a crafted image file. The overflow can corrupt memory or cause the application to crash when decoding the image, preventing normal operation of FFmpeg-based services.
Affected Systems
The flaw exists in FFmpeg, the widely used multimedia framework. Any installation that has not applied the patch that fixes the overflow is potentially vulnerable, regardless of the specific release version listed in this entry.
Risk and Exploitability
The CVSS score is 7.5. The vulnerability is limited to availability impact and is not listed in the CISA KEV catalog. The EPSS score is <1%, indicating a very low probability of exploitation. No public exploit is known; an attacker would need to supply a crafted image through an input channel that uses libswscale, such as a media upload or streaming endpoint.
OpenCVE Enrichment