A heap-based buffer overflow exists in libavformat/http.c in FFmpeg versions prior to 2.8.10, 3.0.5, 3.1.6, and 3.2.2. The vulnerability is triggered when a remote web server sends an HTTP response with a negative chunk size, which is improperly handled by the affected code, leading to a buffer overflow condition.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains two Python exploit scripts targeting a vulnerability in ffmpeg, likely related to improper handling of AVIOContext structures when connecting to a malicious server. Both scripts use the pwntools library to set up a TCP listener on port 12345, simulating a server that ffmpeg will connect to. The main exploit (exploit.py) crafts a complex payload using ROP chains and custom shellcode to achieve remote code execution. Upon successful exploitation, the script delivers a reverse shell payload that connects back to the attacker's machine on 127.1.1.1:1337, granting remote shell access. The exploit requires the attacker to induce the victim's ffmpeg process to connect to their server, after which the exploit triggers a memory corruption, pivots the stack, sets up an executable memory region, writes shellcode, and executes it. The secondary script (exploit crash.py) appears to be a simpler version that triggers the crash and sends a large payload, likely for debugging or proof-of-crash purposes. No hardcoded CVE is referenced, but the exploit is clearly operational and weaponized for remote code execution against vulnerable ffmpeg instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.