Impact
An insufficiently padded extradata field in the MOV parsing path of FFmpeg before version 9.0 allows an out-of-bounds read. Based on the description, it is inferred that this flaw could expose memory contents to an attacker, potentially leaking sensitive data. The vulnerability is classified as CWE‑125, an out-of-bounds read weakness.
Affected Systems
The affected product is FFmpeg, any release earlier than 9.0. This includes all FFmpeg builds prior to the 9.0 series that process MOV container files.
Risk and Exploitability
The CVSS Score is 2.9, the EPSS score is less than 1%, and the issue is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a crafted MOV container to a vulnerable FFmpeg instance; the flaw does not provide control flow hijacking or remote code execution. Consequently the overall data leakage warrants monitoring of any untrusted media input.
OpenCVE Enrichment