---
title: "CVE-2025-1373\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-1373?format=md
keywords: index, follow
---

# CVE-2025-1373

Publication date 17 February 2025

Last updated 3 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**3.3 · Low**

[Score breakdown](https://ubuntu.com/security/CVE-2025-1373?format=md#impact-score)

Toggle side navigation

## Description

A vulnerability was found in FFmpeg up to 7.1. It has been rated as
problematic. Affected by this issue is the function mov\_read\_trak of the
file libavformat/mov.c of the component MOV Parser. The manipulation leads
to null pointer dereference. Local access is required to approach this
attack. The exploit has been disclosed to the public and may be used. The
patch is identified as 43be8d07281caca2e88bfd8ee2333633e1fb1a13. It is
recommended to apply a patch to fix this issue.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| ffmpeg | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| libav | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 25.04 plucky | Not in release |
| 24.10 oracular | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Not in release |
| 14.04 LTS trusty | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

3.3 · Low

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | Low |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 3.3 · Low |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-1373)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-1373)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-1373)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-1373)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-1373>
* <https://ffmpeg.org/>
* <https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/43be8d07281caca2e88bfd8ee2333633e1fb1a13>
* <https://trac.ffmpeg.org/attachment/ticket/11460/poc>
* <https://trac.ffmpeg.org/ticket/11460>
* <https://vuldb.com/?ctiid.295982>
* <https://vuldb.com/?id.295982>
* <https://vuldb.com/?submit.496930>
