Impact
An integer overflow in libswscale/utils.c allows an attacker to trigger a DoS by supplying a crafted image file. The overflow can corrupt memory or cause the application to crash when decoding the image, preventing normal operation of FFmpeg-based services.
Affected Systems
The flaw exists in FFmpeg, the widely used multimedia framework. Any installation that has not applied the patch that fixes the overflow is potentially vulnerable, regardless of the specific release version listed in this entry.
Risk and Exploitability
The vulnerability is limited to availability impact and is not currently listed in the CISA KEV catalog. No public exploit has been reported and the EPSS score is not available, so the likelihood of exploitation is uncertain. An attacker would need to supply a malicious image via an input channel that utilizes libswscale, such as a media upload or streaming endpoint.
OpenCVE Enrichment