← voltar
CVE-2025-8584

libav AVI File Parser buffer.c av_buffer_unref null pointer dereference

CVSS 4.8 MEDIUMEPSS 0.2%CWE-404CWE-476
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 4.8EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
05 ago 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A vulnerability classified as problematic was found in libav up to 12.3. Affected by this vulnerability is the function av_buffer_unref of the file libavutil/buffer.c of the component AVI File Parser. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The bug was initially reported by the researcher to the wrong project. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
n/a · libav

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →