PT-2021-7978 · FFmpeg+4 · Ffmpeg+4

1Vanchen

·

Published

2021-03-01

·

Updated

2024-07-12

·

CVE-2021-28429

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg version 4.3.2
Description The issue is related to an integer overflow vulnerability in the av timecode make string function of the libavutil/timecode.c component in FFmpeg. This vulnerability allows local attackers to cause a denial of service (DoS) via a crafted .mov file.
Recommendations For FFmpeg version 4.3.2, consider updating to a newer version to mitigate the risk, as the current version is affected by the integer overflow vulnerability in the av timecode make string function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-09077
CVE-2021-28429
OESA-2024-1831
OESA-2024-1832
OESA-2024-1833
OESA-2024-1834
OPENSUSE-SU-2023_3818-1
SUSE-SU-2023:3818-1
SUSE-SU-2023_3818-1
USN-6430-1

Affected Products

Astra Linux
Ffmpeg
Linuxmint
Suse
Ubuntu