PT-2020-13937 · FFmpeg · Ffmpeg

Published

2020-06-16

·

Updated

2026-02-06

·

CVE-2020-14212

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to 4.3
Description The issue is related to a heap-based buffer overflow in the avio get str function located in libavformat/aviobuf.c. This overflow occurs because dnn backend native.c calls ff dnn load model native and a specific index check is omitted, leading to the overflow.
Recommendations For FFmpeg versions prior to 4.3, update to version 4.3 or later to resolve the issue.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2020-14212

Affected Products

Ffmpeg