PT-2021-4069 · FFmpeg+1 · Ffmpeg+1

Burak Çarıkçı

·

Published

2021-05-27

·

Updated

2026-02-06

·

CVE-2021-33815

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg version 4.4
Description The issue is related to the dwa uncompress function in the libavcodec/exr.c component of the FFmpeg multimedia library. It involves incorrect checking of dc count, which can lead to an out-of-bounds array access. This could allow a remote attacker to access confidential data, compromise data integrity, and cause a denial of service.
Recommendations For FFmpeg version 4.4, consider disabling the dwa uncompress function in libavcodec/exr.c as a temporary workaround until a patch is available. Restrict access to the libavcodec/exr.c component to minimize the risk of exploitation. Avoid using the dc count variable in the affected function until the issue is resolved.

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3166
ALT-PU-2022-1821
BDU:2021-04610
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2021-33815
OPENSUSE-SU-2024:10754-1

Affected Products

Alt Linux
Ffmpeg