Impact
The flaw is a null pointer dereference in the amf_object_get function of FLVMeta’s AMF Object Parsing module. When the component encounters malformed AMF data, it accesses a null reference, causing the application to crash. The description states that the attack can be initiated remotely and that an exploit has been publicly disclosed, implying that remote attackers can trigger the crash and potentially cause a denial of service on systems running the vulnerable library.
Affected Systems
The affected product is FLVMeta, up to version 1.2.2. Any installation of FLVMeta 1.2.2 or earlier that parses AMF objects is susceptible. The vulnerability is tied to the generic FLVMeta component, not a product line or vendor beyond the repository owner.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, primarily representing application instability rather than data compromise. EPSS is not available, and the issue is not listed in CISA KEV. The attack vector is remote, as malformed input can be supplied over a network or through ingestion of untrusted streams. Exploitation requires that the target host processes AMF data from an attacker, making the risk dependent on the exposure of FLVMeta to external inputs.
OpenCVE Enrichment