/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-pq7q-954c-v24w

Published

Last updated

https://images.chainguard.dev/security/CGA-pq7q-954c-v24w
Package

ffmpeg-6

Repository

Chainguard

Latest Update
Not affected
Aliases
  • CVE-2023-51794
  • GHSA-4425-9m6f-3ppg

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2023-51794

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

The stereowiden buffer overflow vulnerability has been comprehensively fixed in FFmpeg 6.1.2. Two key fixes are present: (1) The 2016 fix (commit 906ee41141) completely rewrote the buffer handling logic to check bounds before any writes, eliminating the race condition. (2) The 2023 fix (commit 50f0f8c53c) added zero-length validation. Current code in libavfilter/af_stereowiden.c shows both fixes implemented - the processing loop checks boundaries before pointer arithmetic (lines 115-130) and initialization includes zero-length check (lines 72-77).

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing