Impact
A heap‑based buffer overflow exists in the amf_string_new function of FLVMeta’s AMF String Processing module due to insufficient validation of the argument length. When an attacker supplies an oversized string, the program writes beyond the allocated heap buffer, corrupting memory integrity and creating the possibility for arbitrary code execution or similar adverse effects. The vulnerability is explicitly identified as remotely exploitable and public proof‑of‑concepts confirm that an attacker can trigger it against a running instance without special privileges.
Affected Systems
The affected product is FLVMeta, an open‑source tool for manipulating FLV files. Versions up to and including 1.2.2 are vulnerable. A patch is available in the repository commit f412a33b9a84c2d1a9dee145a868feddbf64879e and should be applied to any instance using a susceptible version.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity and that remote exploitation is possible. Because the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the formal risk level cannot confirm widespread exploitation, but the public proof‑of‑concept demonstrates real feasibility. The flaw can be triggered over the network, so any exposed FLVMeta invocation is at risk. The lack of an EPSS score does not lessen the need to patch given the proven exploit.
OpenCVE Enrichment