dwa_uncompress in libavcodec/exr.c in FFmpeg 4.4 allows an out-of-bounds array access because dc_count is not strictly checked.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ffmpegUpgrade ffmpeg4 | Aug 22, 2024 | Jun 3, 2021 |
| Ffmpeg | — | Upgrade to FFmpeg version 4.4 | Jun 9, 2021 | Jun 3, 2021 |
| Gentoo Linux | — | Upgrade media-video/ffmpeg. | Dec 27, 2023 | Jun 3, 2021 |
| Suse | — | Upgrade libavresample4_0Upgrade libswresample3_9Upgrade libpostproc55_9Upgrade libavcodec58_134Upgrade libavdevice58_13Upgrade libavfilter7_110Upgrade libswscale5_9Upgrade libavformat58_76Upgrade libavutil56_70 | Oct 26, 2022 | Jun 3, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub