CVE-2024-31585

Publication date 17 April 2024

Last updated 30 May 2025


Ubuntu priority

Cvss 3 Severity Score

5.3 · Medium

Score breakdown

FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability in libavfilter/avf_showspectrum.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

Status

Package Ubuntu Release Status
ffmpeg 25.04 plucky
Not affected
24.10 oracular
Not affected
24.04 LTS noble
Not affected
23.10 mantic
Fixed 7:6.0-6ubuntu1.1
22.04 LTS jammy
Not affected
20.04 LTS focal
Not affected
18.04 LTS bionic
Not affected
16.04 LTS xenial
Not affected

Severity score breakdown

Parameter Value
Base score 5.3 · Medium
Attack vector Local
Attack complexity High
Privileges required Low
User interaction Required
Scope Changed
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H