PT-2021-5754 · FFmpeg+5 · Ffmpeg+5
Maryam Ebrahimzadeh
·
Published
2021-08-06
·
Updated
2026-02-06
·
CVE-2021-38171
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FFmpeg version 4.4
Description
The issue is related to the
adts decode extradata function in the libavformat/adtsenc.c component of the FFmpeg library. It does not check the return value of init get bits, which can be crafted by an attacker. This could allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.Recommendations
For FFmpeg version 4.4, consider disabling the
adts decode extradata function until a patch is available. Restrict access to the libavformat/adtsenc.c module to minimize the risk of exploitation. Avoid using the init get bits function with crafted second arguments in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Unchecked Return Value
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Ffmpeg
Linuxmint
Suse
Ubuntu