PT-2020-6180 · FFmpeg+5 · Ffmpeg+5

Published

2020-10-20

·

Updated

2026-02-06

·

CVE-2020-35965

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg version 4.3.1
Description The issue is related to the decode frame function in the libavcodec/exr.c component, which has an out-of-bounds write due to errors in calculations. This can be exploited by a remote attacker to cause a denial of service.
Recommendations For FFmpeg version 4.3.1, consider updating to a newer version that contains a fix for this issue, as the current version has a flawed decode frame function in libavcodec/exr.c. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1101
ALT-PU-2021-1351
ALT-PU-2021-1662
ALT-PU-2021-3508
BDU:2021-03446
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2020-35965
DLA-2537-1
DSA-4990-1
MGASA-2021-0273
OPENSUSE-SU-2021:3521-1
OPENSUSE-SU-2021_3521-1
SUSE-SU-2021:3521-1
SUSE-SU-2023:0005-1
USN-5167-1
USN-5472-1

Affected Products

Alt Linux
Astra Linux
Ffmpeg
Linuxmint
Suse
Ubuntu