FFmpeg: Info Leak on MP2 Parsing with Bad Section Length
CVE-2023-43555 Published on June 3, 2024
Buffer Over-read in Video
Information disclosure in Video while parsing mp2 clip with invalid section length.
Vulnerability Analysis
CVE-2023-43555 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and a small impact on availability.
Weakness Type
Buffer Over-read
The software reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer. This typically occurs when the pointer or its index is incremented to a position beyond the bounds of the buffer or when pointer arithmetic results in a position outside of the valid memory location to name a few. This may result in exposure of sensitive information or possibly a crash.
Products Associated with CVE-2023-43555
Want to know whenever a new CVE is published for FFmpeg? stack.watch will email you.
Affected Versions
Qualcomm, Inc. Snapdragon:- Version AQT1000 is affected.
- Version FastConnect 6200 is affected.
- Version FastConnect 6700 is affected.
- Version FastConnect 6800 is affected.
- Version FastConnect 6900 is affected.
- Version FastConnect 7800 is affected.
- Version MSM8996AU is affected.
- Version QAM8295P is affected.
- Version QCA6391 is affected.
- Version QCA6420 is affected.
- Version QCA6426 is affected.
- Version QCA6430 is affected.
- Version QCA6436 is affected.
- Version QCA6564A is affected.
- Version QCA6564AU is affected.
- Version QCA6574A is affected.
- Version QCA6574AU is affected.
- Version QCA6696 is affected.
- Version QCM4325 is affected.
- Version QCM4490 is affected.
- Version QCM5430 is affected.
- Version QCM6490 is affected.
- Version QCM8550 is affected.
- Version QCN9074 is affected.
- Version QCS410 is affected.
- Version QCS4490 is affected.
- Version QCS5430 is affected.
- Version QCS610 is affected.
- Version QCS6490 is affected.
- Version QCS7230 is affected.
- Version QCS8250 is affected.
- Version QCS8550 is affected.
- Version Qualcomm 215 Mobile Platform is affected.
- Version Qualcomm Video Collaboration VC1 Platform is affected.
- Version Qualcomm Video Collaboration VC3 Platform is affected.
- Version Qualcomm Video Collaboration VC5 Platform is affected.
- Version SA6145P is affected.
- Version SA6150P is affected.
- Version SA6155P is affected.
- Version SA8145P is affected.
- Version SA8150P is affected.
- Version SA8155P is affected.
- Version SA8195P is affected.
- Version SA8295P is affected.
- Version SD730 is affected.
- Version SD855 is affected.
- Version SD865 5G is affected.
- Version SD888 is affected.
- Version SG4150P is affected.
- Version SM6250 is affected.
- Version SM7250P is affected.
- Version SM7315 is affected.
- Version SM7325P is affected.
- Version SM8550P is affected.
- Version Snapdragon 4 Gen 1 Mobile Platform is affected.
- Version Snapdragon 4 Gen 2 Mobile Platform is affected.
- Version Snapdragon 460 Mobile Platform is affected.
- Version Snapdragon 480 5G Mobile Platform is affected.
- Version Snapdragon 480+ 5G Mobile Platform (SM4350-AC) is affected.
- Version Snapdragon 662 Mobile Platform is affected.
- Version Snapdragon 680 4G Mobile Platform is affected.
- Version Snapdragon 685 4G Mobile Platform (SM6225-AD) is affected.
- Version Snapdragon 690 5G Mobile Platform is affected.
- Version Snapdragon 695 5G Mobile Platform is affected.
- Version Snapdragon 720G Mobile Platform is affected.
- Version Snapdragon 730 Mobile Platform (SM7150-AA) is affected.
- Version Snapdragon 730G Mobile Platform (SM7150-AB) is affected.
- Version Snapdragon 732G Mobile Platform (SM7150-AC) is affected.
- Version Snapdragon 765 5G Mobile Platform (SM7250-AA) is affected.
- Version Snapdragon 765G 5G Mobile Platform (SM7250-AB) is affected.
- Version Snapdragon 768G 5G Mobile Platform (SM7250-AC) is affected.
- Version Snapdragon 778G 5G Mobile Platform is affected.
- Version Snapdragon 778G+ 5G Mobile Platform (SM7325-AE) is affected.
- Version Snapdragon 780G 5G Mobile Platform is affected.
- Version Snapdragon 782G Mobile Platform (SM7325-AF) is affected.
- Version Snapdragon 7c+ Gen 3 Compute is affected.
- Version Snapdragon 8 Gen 1 Mobile Platform is affected.
- Version Snapdragon 8 Gen 2 Mobile Platform is affected.
- Version Snapdragon 8+ Gen 2 Mobile Platform is affected.
- Version Snapdragon 820 Automotive Platform is affected.
- Version Snapdragon 855 Mobile Platform is affected.
- Version Snapdragon 855+/860 Mobile Platform (SM8150-AC) is affected.
- Version Snapdragon 865 5G Mobile Platform is affected.
- Version Snapdragon 865+ 5G Mobile Platform (SM8250-AB) is affected.
- Version Snapdragon 870 5G Mobile Platform (SM8250-AC) is affected.
- Version Snapdragon 888 5G Mobile Platform is affected.
- Version Snapdragon 888+ 5G Mobile Platform (SM8350-AC) is affected.
- Version Snapdragon W5+ Gen 1 Wearable Platform is affected.
- Version Snapdragon Wear 4100+ Platform is affected.
- Version Snapdragon X55 5G Modem-RF System is affected.
- Version Snapdragon XR2 5G Platform is affected.
- Version SW5100 is affected.
- Version SW5100P is affected.
- Version SXR2130 is affected.
- Version WCD9326 is affected.
- Version WCD9341 is affected.
- Version WCD9370 is affected.
- Version WCD9375 is affected.
- Version WCD9380 is affected.
- Version WCD9385 is affected.
- Version WCD9390 is affected.
- Version WCD9395 is affected.
- Version WCN3610 is affected.
- Version WCN3615 is affected.
- Version WCN3660B is affected.
- Version WCN3680B is affected.
- Version WCN3950 is affected.
- Version WCN3980 is affected.
- Version WCN3988 is affected.
- Version WCN6740 is affected.
- Version WSA8810 is affected.
- Version WSA8815 is affected.
- Version WSA8830 is affected.
- Version WSA8832 is affected.
- Version WSA8835 is affected.
- Version WSA8840 is affected.
- Version WSA8845 is affected.
- Version WSA8845H is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
- Version * is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.