CVE-2022-3109 is a high-severity vulnerability in the FFmpeg package, specifically within the vp3_decode_frame function in libavcodec/vp3.c. It stems from a missing return value check for av_malloc(), leading to a null pointer dereference that impacts availability. This affects various distributions including Debian and Fedora, as well as FFmpeg itself. The vulnerability has a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity, resulting in a denial of service. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, nor is exploit code available on platforms like Metasploit or ExploitDB. The vulnerability also lacks significant community discussion or media coverage, suggesting a low level of public awareness or immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
< 5.0.3CPE matchmatch criteria | cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.