Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian LTS: DLA-2742-1 Critical Buffer Overflow Threat in ffmpeg

debian lts
Calendar Grey August 15, 2021
Dist Debian Esm H88
Enhance the ffmpeg version on Debian LTS promptly due to several severe security concerns, including potential buffer overflow flaws. Take immediate action!
Multiple issues have been discovered in ffmpeg

Summary

CVE-2020-21041

Buffer Overflow vulnerability exists via apng_do_inverse_blend in
libavcodec/pngenc.c, which could let a remote malicious user cause a
Denial of Service.

CVE-2020-22015

Buffer Overflow vulnerability in mov_write_video_tag due to the out of
bounds in libavformat/movenc.c, which could let a remote malicious user
obtain sensitive information, cause a Denial of Service, or execute
arbitrary code.

CVE-2020-22016

A heap-based Buffer Overflow vulnerability at libavcodec/get_bits.h when
writing .mov files, which might lead to memory corruption and other
potential consequences.

CVE-2020-22020

Buffer Overflow vulnerability in the build_diff_map function in
libavfilter/vf_fieldmatch.c, which could let a remote malicious user cause
a Denial of Service.

CVE-2020-22021

Buffer Overflow vulnerability at filter_edges function in
libavfilter/vf_yadif.c, which could let a remote malicious user cause a
Denial of Service.

CVE-2020-22022

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: ffmpeg
Version: 7:3.2.15-0+deb9u3
CVE ID: CVE-2020-21041 CVE-2020-22015 CVE-2020-22016 CVE-2020-22020

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here