JLSEC-2025-150

    Dashboard / Vulnerabilities / JLSEC-2025-150

    JLSEC-2025-150

    Published: 19 Oct 2025Last Modified: 23 Jul 2026
    Upstream:

    Summary: A vulnerability was found in FFmpeg up to 7.1

    Details: A vulnerability was found in FFmpeg up to 7.1. It has been rated as problematic. Affected by this issue is the function `mov_read_trak` of the file `libavformat/mov.c` of the component MOV Parser. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The patch is identified as 43be8d07281caca2e88bfd8ee2333633e1fb1a13. It is recommended to apply a patch to fix this issue.

    Affected packages

    Package

    Name: FFMPEG_jll

    Purl: pkg:julia/FFMPEG_jll?uuid=b22a6f82-2f65-5046-a5b2-351ab43fb4e5

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -7.1.1+0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    JLSEC-2025-150 | CVE-DB