PT-2019-5409 · FFmpeg+3 · Ffmpeg+3

Published

2019-02-21

·

Updated

2026-02-06

·

CVE-2020-12284

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg versions 4.1 through 4.2.2
Description The issue is related to a heap-based buffer overflow in the cbs jpeg split fragment function during JPEG MARKER SOS handling due to a missing length check. This can lead to a denial of service. The vulnerability can be exploited by a remote attacker.
Recommendations For FFmpeg versions 4.1 through 4.2.2, consider updating to a newer version that includes a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1275
ALT-PU-2020-2008
ALT-PU-2020-2032
BDU:2020-02828
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2020-12284
DSA-4722-1
MGASA-2020-0290
USN-4431-1

Affected Products

Alt Linux
Ffmpeg
Linuxmint
Ubuntu