PT-2019-6196 · FFmpeg+5 · Ffmpeg+5
Published
2019-10-13
·
Updated
2024-04-29
·
CVE-2020-20898
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ffmpeg version 4.2.1
Description
The issue is related to an Integer Overflow vulnerability in the
filter16 prewitt function within the libavfilter/vf convolution.c component of the Ffmpeg library. This vulnerability can be exploited by a remote attacker to cause a Denial of Service or gain access to confidential data, compromise its integrity.Recommendations
For Ffmpeg version 4.2.1, consider applying a patch or updating to a newer version that addresses the Integer Overflow vulnerability in the
filter16 prewitt function, if available. As a temporary workaround, consider restricting access to the libavfilter/vf convolution.c component to minimize the risk of exploitation.Exploit
Fix
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Ffmpeg
Linuxmint
Suse
Ubuntu