Impact
A flaw in the parse_playlist function of FFmpeg 8.0.x allows an attacker to manipulate the duration/target_duration argument, causing a crash and resulting in a denial of service. The weakness is an improper use of input parameters that leads to resource exhaustion or application termination.
Affected Systems
The vulnerability affects the FFmpeg library, specifically versions 8.0.x. Upgrading to FFmpeg 8.1 or later, or to issue.
Risk and Exploitability
The CVSS base score is 5.3, indicating moderate severity. The EPSS score is < 1% (approximately 0.0035), but the attack can be performed remotely, making the risk contingent on exposure to untrusted inputs. The vulnerability is not listed in the CISA KEV catalog, implying no known large-scale exploitation to date.
OpenCVE Enrichment