Linuxsecurity SUSE ffmpeg-4 Security Fixes Address Multiple Vulnerabilities
Article Content
- •SUSE released an important update for ffmpeg-4 on June 18, 2026.
- •The update addresses multiple vulnerabilities, including buffer overflows and unsafe file extension bypass.
- •Affected CVEs include CVE-2023-6601, CVE-2024-35366, and CVE-2025-1594.
SUSE released an important update for ffmpeg-4 on June 18, 2026, addressing several vulnerabilities. The update includes fixes for CVE-2023-6601, CVE-2024-35366, CVE-2025-1594, CVE-2025-9951, CVE-2025-10256, and CVE-2025-63757. These vulnerabilities include issues such as an HLS Unsafe File Extension Bypass and multiple buffer overflows that could lead to denial of service. The vulnerabilities affect the ffmpeg-4 software, which is widely used for multimedia processing. Security ratings for these vulnerabilities range from 3.3 to 6.9 on the CVSS scale, indicating varying levels of severity. Users are urged to apply the updates promptly to mitigate potential risks. The vulnerabilities were identified in various components of ffmpeg, including libavformat and libavcodec. This update is crucial for maintaining the security of systems utilizing ffmpeg.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2023-6601 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing significant risks to…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…