/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-x24c-cp8x-wp3h

Published

Last updated

https://images.chainguard.dev/security/CGA-x24c-cp8x-wp3h
Package

ffmpeg-6

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-0518
  • GHSA-vp3p-57c4-r559

Severity

5.3

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-0518

Updates

Status

Pending upstream fix

Impact

The pan filter floating point exception vulnerability is NOT fixed in FFmpeg 6.1.2. The fix (commit b5b6391d64) from January 2025 is not present. The vulnerable code at libavfilter/af_pan.c:176 uses sscanf return value incorrectly - when sscanf returns EOF (-1), it's treated as true, causing arg += len with uninitialized len value. Upstream fix properly checks sscanf return value and returns error on failure. This fix needs to be backported to FFmpeg 6.1.2.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing