← Back
Web Application
CVE-2026-66040 high CVSS 8.8

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...

Summary

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...

AI summary openai / gpt-4o

FFmpeg 8.1.2以前のバージョンには、PNGおよびAPNGエンコーダ内にヒープアウトオブバウンズ書き込みの脆弱性があります。この脆弱性により、悪意のあるeXIfチャンクを含むPNG画像を使用して、リモート攻撃者がヒープメモリを破損し、任意のコードを実行する可能性があります。
❓ What is the problem
FFmpegでのヒープアウトオブバウンズ書き込みの脆弱性。
📍 Affected scope
PNGおよびAPNGエンコーダ内で発生。
🔥 Severity
リモート攻撃者が任意のコードを実行可能なため、重大。CVSSスコアは8.8。
🔧 How to fix
脆弱性はcommit b506fafで修正されている。最新バージョンにアップデートすることで対策可能。
🛡️ Workaround
情報なし
🔍 Detection
情報なし

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →