{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"High"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"ffmpeg security update",
				"category":"general",
				"title":"Synopsis"
			},
			{
				"text":"An update for ffmpeg is now available for openEuler-24.03-LTS-SP1",
				"category":"general",
				"title":"Summary"
			},
			{
				"text":"FFmpeg is a complete and free Internet live audio and video broadcasting solution for Linux/Unix. It also includes a digital VCR. It can encode in real time in many formats including MPEG1 audio and video, MPEG4, h263, ac3, asf, avi, real, mjpeg, and flash.\n\nSecurity Fix(es):\n\nWhen calculating the content path in handling of MPEG-DASH manifests, there's an out-of-bounds NUL-byte write one byte past the end of the buffer.When we call xmlNodeGetContent below [0], it returns a buffer precisely allocated to match the string length, using strdup internally. If this buffer is not an empty string, it is assigned to root_url at [1].If the last (non-NUL) byte in this buffer is not '/' then we append '/' in-place at [2]. This will write two bytes into the buffer, starting at the last valid byte in the buffer, writing the NUL byte beyond the end of the allocated buffer.\nWe recommend upgrading to version 8.0 or beyond.(CVE-2025-59728)",
				"category":"general",
				"title":"Description"
			},
			{
				"text":"An update for ffmpeg is now available for openEuler-24.03-LTS-SP1.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
				"category":"general",
				"title":"Topic"
			},
			{
				"text":"High",
				"category":"general",
				"title":"Severity"
			},
			{
				"text":"ffmpeg",
				"category":"general",
				"title":"Affected Component"
			}
		],
		"publisher":{
			"issuing_authority":"openEuler security committee",
			"name":"openEuler",
			"namespace":"https://www.openeuler.org",
			"contact_details":"openeuler-security@openeuler.org",
			"category":"vendor"
		},
		"references":[
			{
				"summary":"openEuler-SA-2026-2665",
				"category":"self",
				"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2665"
			},
			{
				"summary":"CVE-2025-59728",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-59728&packageName=ffmpeg"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59728"
			},
			{
				"summary":"openEuler-SA-2026-2665 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-2665.json"
			}
		],
		"title":"An update for ffmpeg is now available for openEuler-24.03-LTS-SP1",
		"tracking":{
			"initial_release_date":"2026-06-18T16:17:33+08:00",
			"revision_history":[
				{
					"date":"2026-06-18T16:17:33+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				}
			],
			"generator":{
				"date":"2026-06-18T16:17:33+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2026-06-18T16:17:33+08:00",
			"id":"openEuler-SA-2026-2665",
			"version":"1.0.0",
			"status":"final"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"openEuler-24.03-LTS-SP1",
									"name":"openEuler-24.03-LTS-SP1"
								},
								"name":"openEuler-24.03-LTS-SP1",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"aarch64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"ffmpeg-6.1.1-28.oe2403sp1.aarch64.rpm",
									"name":"ffmpeg-6.1.1-28.oe2403sp1.aarch64.rpm"
								},
								"name":"ffmpeg-6.1.1-28.oe2403sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"ffmpeg-debuginfo-6.1.1-28.oe2403sp1.aarch64.rpm",
									"name":"ffmpeg-debuginfo-6.1.1-28.oe2403sp1.aarch64.rpm"
								},
								"name":"ffmpeg-debuginfo-6.1.1-28.oe2403sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"ffmpeg-debugsource-6.1.1-28.oe2403sp1.aarch64.rpm",
									"name":"ffmpeg-debugsource-6.1.1-28.oe2403sp1.aarch64.rpm"
								},
								"name":"ffmpeg-debugsource-6.1.1-28.oe2403sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"ffmpeg-devel-6.1.1-28.oe2403sp1.aarch64.rpm",
									"name":"ffmpeg-devel-6.1.1-28.oe2403sp1.aarch64.rpm"
								},
								"name":"ffmpeg-devel-6.1.1-28.oe2403sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"ffmpeg-libs-6.1.1-28.oe2403sp1.aarch64.rpm",
									"name":"ffmpeg-libs-6.1.1-28.oe2403sp1.aarch64.rpm"
								},
								"name":"ffmpeg-libs-6.1.1-28.oe2403sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"libavdevice-6.1.1-28.oe2403sp1.aarch64.rpm",
									"name":"libavdevice-6.1.1-28.oe2403sp1.aarch64.rpm"
								},
								"name":"libavdevice-6.1.1-28.oe2403sp1.aarch64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"ffmpeg-6.1.1-28.oe2403sp1.src.rpm",
									"name":"ffmpeg-6.1.1-28.oe2403sp1.src.rpm"
								},
								"name":"ffmpeg-6.1.1-28.oe2403sp1.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"x86_64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"ffmpeg-6.1.1-28.oe2403sp1.x86_64.rpm",
									"name":"ffmpeg-6.1.1-28.oe2403sp1.x86_64.rpm"
								},
								"name":"ffmpeg-6.1.1-28.oe2403sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"ffmpeg-debuginfo-6.1.1-28.oe2403sp1.x86_64.rpm",
									"name":"ffmpeg-debuginfo-6.1.1-28.oe2403sp1.x86_64.rpm"
								},
								"name":"ffmpeg-debuginfo-6.1.1-28.oe2403sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"ffmpeg-debugsource-6.1.1-28.oe2403sp1.x86_64.rpm",
									"name":"ffmpeg-debugsource-6.1.1-28.oe2403sp1.x86_64.rpm"
								},
								"name":"ffmpeg-debugsource-6.1.1-28.oe2403sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"ffmpeg-devel-6.1.1-28.oe2403sp1.x86_64.rpm",
									"name":"ffmpeg-devel-6.1.1-28.oe2403sp1.x86_64.rpm"
								},
								"name":"ffmpeg-devel-6.1.1-28.oe2403sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"ffmpeg-libs-6.1.1-28.oe2403sp1.x86_64.rpm",
									"name":"ffmpeg-libs-6.1.1-28.oe2403sp1.x86_64.rpm"
								},
								"name":"ffmpeg-libs-6.1.1-28.oe2403sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP1"
									},
									"product_id":"libavdevice-6.1.1-28.oe2403sp1.x86_64.rpm",
									"name":"libavdevice-6.1.1-28.oe2403sp1.x86_64.rpm"
								},
								"name":"libavdevice-6.1.1-28.oe2403sp1.x86_64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"ffmpeg-6.1.1-28.oe2403sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:ffmpeg-6.1.1-28.oe2403sp1.aarch64",
					"name":"ffmpeg-6.1.1-28.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"ffmpeg-debuginfo-6.1.1-28.oe2403sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:ffmpeg-debuginfo-6.1.1-28.oe2403sp1.aarch64",
					"name":"ffmpeg-debuginfo-6.1.1-28.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"ffmpeg-debugsource-6.1.1-28.oe2403sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:ffmpeg-debugsource-6.1.1-28.oe2403sp1.aarch64",
					"name":"ffmpeg-debugsource-6.1.1-28.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"ffmpeg-devel-6.1.1-28.oe2403sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:ffmpeg-devel-6.1.1-28.oe2403sp1.aarch64",
					"name":"ffmpeg-devel-6.1.1-28.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"ffmpeg-libs-6.1.1-28.oe2403sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:ffmpeg-libs-6.1.1-28.oe2403sp1.aarch64",
					"name":"ffmpeg-libs-6.1.1-28.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"libavdevice-6.1.1-28.oe2403sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:libavdevice-6.1.1-28.oe2403sp1.aarch64",
					"name":"libavdevice-6.1.1-28.oe2403sp1.aarch64 as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"ffmpeg-6.1.1-28.oe2403sp1.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:ffmpeg-6.1.1-28.oe2403sp1.src",
					"name":"ffmpeg-6.1.1-28.oe2403sp1.src as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"ffmpeg-6.1.1-28.oe2403sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:ffmpeg-6.1.1-28.oe2403sp1.x86_64",
					"name":"ffmpeg-6.1.1-28.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"ffmpeg-debuginfo-6.1.1-28.oe2403sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:ffmpeg-debuginfo-6.1.1-28.oe2403sp1.x86_64",
					"name":"ffmpeg-debuginfo-6.1.1-28.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"ffmpeg-debugsource-6.1.1-28.oe2403sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:ffmpeg-debugsource-6.1.1-28.oe2403sp1.x86_64",
					"name":"ffmpeg-debugsource-6.1.1-28.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"ffmpeg-devel-6.1.1-28.oe2403sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:ffmpeg-devel-6.1.1-28.oe2403sp1.x86_64",
					"name":"ffmpeg-devel-6.1.1-28.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"ffmpeg-libs-6.1.1-28.oe2403sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:ffmpeg-libs-6.1.1-28.oe2403sp1.x86_64",
					"name":"ffmpeg-libs-6.1.1-28.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP1",
				"product_reference":"libavdevice-6.1.1-28.oe2403sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP1:libavdevice-6.1.1-28.oe2403sp1.x86_64",
					"name":"libavdevice-6.1.1-28.oe2403sp1.x86_64 as a component of openEuler-24.03-LTS-SP1"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2025-59728",
			"notes":[
				{
					"text":"When calculating the content path in handling of MPEG-DASH manifests, there's an out-of-bounds NUL-byte write one byte past the end of the buffer.When we call xmlNodeGetContent below [0], it returns a buffer precisely allocated to match the string length, using strdup internally. If this buffer is not an empty string, it is assigned to root_url at [1].If the last (non-NUL) byte in this buffer is not '/' then we append '/' in-place at [2]. This will write two bytes into the buffer, starting at the last valid byte in the buffer, writing the NUL byte beyond the end of the allocated buffer.\nWe recommend upgrading to version 8.0 or beyond.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP1:ffmpeg-6.1.1-28.oe2403sp1.aarch64",
					"openEuler-24.03-LTS-SP1:ffmpeg-debuginfo-6.1.1-28.oe2403sp1.aarch64",
					"openEuler-24.03-LTS-SP1:ffmpeg-debugsource-6.1.1-28.oe2403sp1.aarch64",
					"openEuler-24.03-LTS-SP1:ffmpeg-devel-6.1.1-28.oe2403sp1.aarch64",
					"openEuler-24.03-LTS-SP1:ffmpeg-libs-6.1.1-28.oe2403sp1.aarch64",
					"openEuler-24.03-LTS-SP1:libavdevice-6.1.1-28.oe2403sp1.aarch64",
					"openEuler-24.03-LTS-SP1:ffmpeg-6.1.1-28.oe2403sp1.src",
					"openEuler-24.03-LTS-SP1:ffmpeg-6.1.1-28.oe2403sp1.x86_64",
					"openEuler-24.03-LTS-SP1:ffmpeg-debuginfo-6.1.1-28.oe2403sp1.x86_64",
					"openEuler-24.03-LTS-SP1:ffmpeg-debugsource-6.1.1-28.oe2403sp1.x86_64",
					"openEuler-24.03-LTS-SP1:ffmpeg-devel-6.1.1-28.oe2403sp1.x86_64",
					"openEuler-24.03-LTS-SP1:ffmpeg-libs-6.1.1-28.oe2403sp1.x86_64",
					"openEuler-24.03-LTS-SP1:libavdevice-6.1.1-28.oe2403sp1.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP1:ffmpeg-6.1.1-28.oe2403sp1.aarch64",
						"openEuler-24.03-LTS-SP1:ffmpeg-debuginfo-6.1.1-28.oe2403sp1.aarch64",
						"openEuler-24.03-LTS-SP1:ffmpeg-debugsource-6.1.1-28.oe2403sp1.aarch64",
						"openEuler-24.03-LTS-SP1:ffmpeg-devel-6.1.1-28.oe2403sp1.aarch64",
						"openEuler-24.03-LTS-SP1:ffmpeg-libs-6.1.1-28.oe2403sp1.aarch64",
						"openEuler-24.03-LTS-SP1:libavdevice-6.1.1-28.oe2403sp1.aarch64",
						"openEuler-24.03-LTS-SP1:ffmpeg-6.1.1-28.oe2403sp1.src",
						"openEuler-24.03-LTS-SP1:ffmpeg-6.1.1-28.oe2403sp1.x86_64",
						"openEuler-24.03-LTS-SP1:ffmpeg-debuginfo-6.1.1-28.oe2403sp1.x86_64",
						"openEuler-24.03-LTS-SP1:ffmpeg-debugsource-6.1.1-28.oe2403sp1.x86_64",
						"openEuler-24.03-LTS-SP1:ffmpeg-devel-6.1.1-28.oe2403sp1.x86_64",
						"openEuler-24.03-LTS-SP1:ffmpeg-libs-6.1.1-28.oe2403sp1.x86_64",
						"openEuler-24.03-LTS-SP1:libavdevice-6.1.1-28.oe2403sp1.x86_64"
					],
					"details":"ffmpeg security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2665"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP1:ffmpeg-6.1.1-28.oe2403sp1.aarch64",
						"openEuler-24.03-LTS-SP1:ffmpeg-debuginfo-6.1.1-28.oe2403sp1.aarch64",
						"openEuler-24.03-LTS-SP1:ffmpeg-debugsource-6.1.1-28.oe2403sp1.aarch64",
						"openEuler-24.03-LTS-SP1:ffmpeg-devel-6.1.1-28.oe2403sp1.aarch64",
						"openEuler-24.03-LTS-SP1:ffmpeg-libs-6.1.1-28.oe2403sp1.aarch64",
						"openEuler-24.03-LTS-SP1:libavdevice-6.1.1-28.oe2403sp1.aarch64",
						"openEuler-24.03-LTS-SP1:ffmpeg-6.1.1-28.oe2403sp1.src",
						"openEuler-24.03-LTS-SP1:ffmpeg-6.1.1-28.oe2403sp1.x86_64",
						"openEuler-24.03-LTS-SP1:ffmpeg-debuginfo-6.1.1-28.oe2403sp1.x86_64",
						"openEuler-24.03-LTS-SP1:ffmpeg-debugsource-6.1.1-28.oe2403sp1.x86_64",
						"openEuler-24.03-LTS-SP1:ffmpeg-devel-6.1.1-28.oe2403sp1.x86_64",
						"openEuler-24.03-LTS-SP1:ffmpeg-libs-6.1.1-28.oe2403sp1.x86_64",
						"openEuler-24.03-LTS-SP1:libavdevice-6.1.1-28.oe2403sp1.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2025-59728"
		}
	]
}