CVE-2023-6604

A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*

History

03 Nov 2025, 20:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/07/msg00004.html -

Information

Published : 2025-01-06 17:15

Updated : 2025-11-03 20:16


NVD link : CVE-2023-6604

Mitre link : CVE-2023-6604

CVE.ORG link : CVE-2023-6604


JSON object : View

Products Affected

ffmpeg

  • ffmpeg
CWE
CWE-99

Improper Control of Resource Identifiers ('Resource Injection')

CWE-94

Improper Control of Generation of Code ('Code Injection')