PT-2020-6396 · FFmpeg+1 · Ffmpeg+1

Published

2020-06-07

·

Updated

2026-02-06

·

CVE-2020-24020

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFMpeg version 4.2.3
Description The issue is related to a Buffer Overflow vulnerability in the dnn execute layer pad function of the libavfilter/dnn/dnn backend native layer pad.c component. This vulnerability occurs due to a call to memcpy without proper length checks, which could allow a remote malicious user to execute arbitrary code. Exploitation of this vulnerability may also enable the attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For FFMpeg version 4.2.3, consider disabling the dnn execute layer pad function in the libavfilter/dnn/dnn backend native layer pad.c component as a temporary workaround until a patch is available. Restrict access to the libavfilter module to minimize the risk of exploitation. Avoid using the memcpy function without proper length checks in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2361
ALT-PU-2020-2427
BDU:2021-04596
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2020-24020

Affected Products

Alt Linux
Ffmpeg