PT-2021-6711 · FFmpeg+3 · Ffmpeg+3

Published

2020-01-09

·

Updated

2023-01-02

·

CVE-2020-20891

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ffmpeg version 4.2.1
Description The issue is related to a Buffer Overflow in the config input function within the libavfilter/vf gblur.c component of the Ffmpeg library. This allows attackers to potentially cause a Denial of Service or achieve other unspecified impacts. The vulnerability is also associated with unchecked buffer copying, which can be exploited by a remote attacker to access confidential data, compromise its integrity, and cause a service disruption.
Recommendations For Ffmpeg version 4.2.1, consider disabling the config input function in libavfilter/vf gblur.c as a temporary workaround to mitigate the risk of exploitation. Restrict access to sensitive data and ensure proper input validation to minimize the impact of this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1014
ALT-PU-2020-2032
BDU:2022-02072
CVE-2020-20891
DLA-3010-1
DSA-5126-1
OPENSUSE-SU-2021:3521-1
OPENSUSE-SU-2021_3521-1
SUSE-SU-2021:3521-1
SUSE-SU-2021_3521-1
SUSE-SU-2023:0005-1
SUSE-SU-2023_0005-1

Affected Products

Alt Linux
Astra Linux
Ffmpeg
Suse