Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian: DLA-2818-1 Critical: ffmpeg Denial Of Service Threats

debian lts
Calendar Grey November 14, 2021
Dist Debian Esm H88
Debian LTS Advisory DLA-2819-1 provides essential updates for libpng that mitigate potential security vulnerabilities.
Multiple issues have been discovered in ffmpeg - tools for transcoding, streaming and playing of multimedia files

Summary

CVE-2020-20445

Divide By Zero issue via libavcodec/lpc.h, which allows a remote malicious
user to cause a Denial of Service.

CVE-2020-20446

Divide By Zero issue via libavcodec/aacpsy.c, which allows a remote malicious
user to cause a Denial of Service.

CVE-2020-20451

Denial of Service issue due to resource management errors via
fftools/cmdutils.c.

CVE-2020-20453

Divide By Zero issue via libavcodec/aaccoder, which allows a remote
malicious user to cause a Denial of Service.

CVE-2020-22037

A Denial of Service vulnerability due to a memory leak in
avcodec_alloc_context3 at options.c

CVE-2020-22041

A Denial of Service vulnerability due to a memory leak in
the av_buffersrc_add_frame_flags function in buffersrc.

CVE-2020-22044

A Denial of Service vulnerability due to a memory leak in the
url_open_dyn_buf_internal function in libavformat/aviobuf.c.

CVE-2020-22046

A Denial of Service vulnerability due to a memory leak in the

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: ffmpeg
Version: 7:3.2.16-1+deb9u1
CVE ID: CVE-2020-20445 CVE-2020-20446 CVE-2020-20451 CVE-2020-20453

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here