PT-2021-6711 · FFmpeg+3 · Ffmpeg+3
Published
2020-01-09
·
Updated
2023-01-02
·
CVE-2020-20891
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ffmpeg version 4.2.1
Description
The issue is related to a Buffer Overflow in the
config input function within the libavfilter/vf gblur.c component of the Ffmpeg library. This allows attackers to potentially cause a Denial of Service or achieve other unspecified impacts. The vulnerability is also associated with unchecked buffer copying, which can be exploited by a remote attacker to access confidential data, compromise its integrity, and cause a service disruption.Recommendations
For Ffmpeg version 4.2.1, consider disabling the
config input function in libavfilter/vf gblur.c as a temporary workaround to mitigate the risk of exploitation. Restrict access to sensitive data and ensure proper input validation to minimize the impact of this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Ffmpeg
Suse