ffmpeg
Version: 8.1.1Mirror of https://git.ffmpeg.org/ffmpeg.git
What is ffmpeg?
Mirror of https://git.ffmpeg.org/ffmpeg.git
How to use this package
Quick install
Installs the package into the current environment for this session. Use --build or --runtime to persist it as a build-time or runtime dependency.
min add ffmpeg Declare as a task dependency in minimal.toml
Listing the package under tasks.<name>.packages makes it available inside that task’s sandbox.
[tasks.dev]
packages = ["ffmpeg"] Build-time vs runtime
Choose build-time for tools needed during compilation, runtime for dynamic libraries loaded at runtime.
min add --build ffmpeg
min add --runtime ffmpeg Dependencies (21)
| Name | Version | Kind |
|---|---|---|
| base | — | build |
| dav1d | 1.5.3 | runtime |
| fontconfig | 2.17.1 | runtime |
| freetype | 2.14.1 | runtime |
| fribidi | 1.0.16 | runtime |
| harfbuzz | 14.2.0 | runtime |
| libaom | 3.13.1 | runtime |
| libass | 0.17.4 | runtime |
| libfdk-aac | 2.0.3 | runtime |
| libopus | 1.6.1 | runtime |
| libsvtav1 | 4.0.1 | runtime |
| libvmaf | 3.0.0 | runtime |
| libvpx | 1.16.0 | runtime |
| libx264 | 0.165.3222 | runtime |
| libx265 | 4.1 | runtime |
| make | 4.4.1 | build |
| openssl CVE:1 | 3.6.2 | runtime |
| pkgconf | 2.5.1 | build |
| toolchain | — | build |
| xz | 5.8.3 | runtime |
| zlib | 1.3.2 | runtime |
No dependants
No other packages in the registry depend on this one.
No direct advisories
This package inherits 14 transitive advisories from its dependencies.
Showing 14 transitive advisories via ffmpeg's dependencies
No advisories match the current filters.
| Status | IDs | Package | Severity | |||
|---|---|---|---|---|---|---|
| Critical ( 0 ) | ||||||
| High ( 12 ) | ||||||
| Affected: 2.42 | glibc | High: 7.5 | ||||
SummaryNo summary published for this advisory. Affected ranges
CVSS vector:
References | ||||||
| Affected: 2.42 | glibc | High: 7.5 | ||||
SummaryNo summary published for this advisory. Affected ranges
CVSS vector:
References | ||||||
| Affected: 2.42 | glibc | High: 8.4 | ||||
SummaryNo summary published for this advisory. Affected ranges
CVSS vector:
| ||||||
| Affected: 3.6.2 | openssl | High: 7.5 | ||||
SummaryNo summary published for this advisory. Via: openssl Affected ranges
CVSS vector:
References
| ||||||
| Resolved in 9ceb800ac26fd81a5eaf27ef366d5fce47e80447 | harfbuzz | High | ||||
SummaryHeap-buffer-overflow in OT::cvar::decompile_tuple_variations Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Resolved in 4e2f409bce77b97de2d098365977beeeb4447b1e | harfbuzz | High | ||||
SummaryHeap-use-after-free in hb_bit_set_invertible_t::next Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Resolved in 4e2f409bce77b97de2d098365977beeeb4447b1e | harfbuzz | High | ||||
SummaryHeap-use-after-free in OT::CoverageFormat1::intersected_coverage_glyphs Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Resolved in 4e2f409bce77b97de2d098365977beeeb4447b1e | harfbuzz | High | ||||
SummaryHeap-use-after-free in hb_bit_set_invertible_t::intersects Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Resolved in 0df65d82dbc41e8da00adb243de5918db532c8a6 | openssl | High | ||||
SummaryHeap-buffer-overflow in asn1_ex_i2c Via: openssl Affected ranges
Fixed in:
References | ||||||
| Resolved in 00fdbca4f6a5c4623b9c4838da502cccce8aaa74 | harfbuzz | High | ||||
SummaryHeap-buffer-overflow in BEInt<unsigned short, 2>::operator unsigned short Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Resolved in 00fdbca4f6a5c4623b9c4838da502cccce8aaa74 | harfbuzz | High | ||||
SummaryHeap-buffer-overflow in BEInt<unsigned short, 2>::operator unsigned short Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Resolved in 7a6686a589ed6bf17a5af0b8012501e4d4ee2ded | harfbuzz | High | ||||
SummaryHeap-buffer-overflow in BEInt<unsigned short, 2>::operator unsigned short Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Medium ( 2 ) | ||||||
| Under investigation | libpng | Medium: 5.4 | ||||
SummaryLIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controlled bytes inside an ignored ancillary chunk to be reinterpreted as a fresh chunk header on the next call to `png_process_data`. Commit faf06924688b62d7c1654b5ceddedbde66ffadb4 fixes the issue. Affected ranges
CVSS vector:
| ||||||
| Resolved in 04d60de6ae06562262f04e8e2e4d9441c66233e0 | harfbuzz | Medium | ||||
SummaryUse-of-uninitialized-value in CFF::cff2_cs_opset_t<cff2_cs_opset_subr_subset_t, CFF::subr_subset_param_t, CFF: Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Low ( 0 ) | ||||||
| Unknown ( 0 ) | ||||||
74 components
No components match your filter.
| Packages | Version |
|---|---|
| ffmpeg ROOT | 8.1.1 |
| acl | 2.3.2 |
| attr | 2.5.2 |
| autoconf | 2.73 |
| automake | 1.18.1 |
| bash | 5.3 |
| bash-bootstrap | 5.3 |
| binutils | 2.46.1 |
| bison | 3.8.2 |
| bzip2 | 1.0.8 |
| cmake | 4.2.3 |
| coreutils | 9.11 |
| curl | 8.20.0 |
| dav1d | 1.5.3 |
| diffutils | 3.12 |
| expat | 2.7.5 |
| file | 5.47 |
| findutils | 4.10.0 |
| flex | 2.6.4 |
| fontconfig | 2.17.1 |
| freetype | 2.14.1 |
| fribidi | 1.0.16 |
| gawk | 5.4.0 |
| gawk-bootstrap | 5.3.2 |
| gcc | 15.2.0 |
| gdbm | 1.26 |
| glib | 2.86.4 |
| glibc | 2.42 |
| gmp | 6.3.0 |
| gperf | 3.1 |
| grep | 3.12 |
| gzip | 1.14 |
| harfbuzz | 14.2.0 |
| libaom | 3.13.1 |
| libass | 0.17.4 |
| libcap | 2.78 |
| libfdk-aac | 2.0.3 |
| libffi | 3.5.2 |
| libidn2 | 2.3.8 |
| libopus | 1.6.1 |
| libpng | 1.6.58 |
| libpsl | 0.21.5 |
| libsvtav1 | 4.0.1 |
| libtool | 2.5.4 |
| libunistring | 1.4.1 |
| libuv | 1.52.1 |
| libvmaf | 3.0.0 |
| libvpx | 1.16.0 |
| libx264 | 0.165.3222 |
| libx265 | 4.1 |
| linux_headers | 6.12.43 |
| lz4 | 1.10.0 |
| m4 | 1.4.21 |
| make | 4.4.1 |
| meson | 1.10.1 |
| mpc | 1.4.0 |
| mpfr | 4.2.2 |
| nasm | 3.01 |
| ncurses | 6.5-20250830 |
| ninja | 1.13.2 |
| openssl | 3.6.2 |
| pcre2 | 10.47 |
| perl | 5.42.0 |
| pkgconf | 2.5.1 |
| python | 3.14.5 |
| readline | 8.3 |
| sed | 4.9 |
| setuptools | 82.0.1 |
| sqlite | 3.50.4 |
| tar | 1.35 |
| util-linux | 2.42.1 |
| xz | 5.8.3 |
| zlib | 1.3.2 |
| zstd | 1.5.7 |