/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-rmj9-f74p-7pqh

Published

Last updated

https://images.chainguard.dev/security/CGA-rmj9-f74p-7pqh
Package

ffmpeg-6

Repository

Chainguard

Latest Update
Not affected
Aliases
  • CVE-2023-51797
  • GHSA-3mxv-473p-h624

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2023-51797

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

The showwaves buffer overflow vulnerability has been fixed in FFmpeg 6.1.2. The fix (commit 08bd2cbfeb) added a check for history_nb_samples <= 0 at libavfilter/avf_showwaves.c:441-446. This prevents invalid buffer allocation when av_rescale returns 0 or negative values. Without the check, av_calloc(0, ...) would return NULL, causing crashes when later code accesses showwaves->history[i]. The fix ensures the function returns an error before any invalid allocation occurs.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing