Impact
An integer overflow in FFmpeg's target_sws_fuzzer() function allows an attacker to trigger a crash, leading to a denial of service. The overflow occurs during processing of crafted input that can be supplied by a client or network traffic. The vulnerability disrupts FFmpeg's operation without requiring code execution or elevated privileges.
Affected Systems
FFmpeg, any build that includes the vulnerable target_sws_fuzzer() function. The description does not specify version details, so all versions prior to the patch that contains the fixed code are potentially affected.
Risk and Exploitability
EPSS is not available and the vulnerability is not listed in CISA KEV. No CVSS score was provided. Because the flaw requires only a crafted payload and does not grant code execution, the risk is lower than high‑severity exploits, but a DoS can disrupt services. The likely attack vector is a remote client sending malicious media or fuzzer input to a service that uses FFmpeg.
OpenCVE Enrichment