A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ffmpeg | Nov 29, 2021 | Jun 2, 2021 |
| Ffmpeg | — | Upgrade to FFmpeg version 4.3 | Jun 9, 2021 | Jun 2, 2021 |
| Suse | — | Upgrade libswresample-develUpgrade libpostproc54Upgrade libavfilter6Upgrade libswresample2-32bitUpgrade libpostproc-develUpgrade libavresample3-64bitUpgrade libavfilter6-32bitUpgrade libavutil-develUpgrade libavcodec-develUpgrade libavcodec57-32bitUpgrade libpostproc54-32bitUpgrade libavformat57-32bitUpgrade ffmpegUpgrade libavfilter-develUpgrade libavcodec57Upgrade libavdevice57-32bitUpgrade libavformat57Upgrade libavdevice57Upgrade libavdevice-develUpgrade libavutil55-32bitUpgrade libavformat-develUpgrade libswresample2Upgrade ffmpeg-private-develUpgrade libavresample-develUpgrade libswscale4Upgrade libavutil55Upgrade libswscale4-32bitUpgrade libavresample3Upgrade libswscale-develUpgrade libavresample3-32bit | Sep 3, 2021 | Jun 2, 2021 |
| Ubuntu | — | Upgrade libavformat-ffmpeg56 (Ubuntu Pro)Upgrade libavcodec-extra (Ubuntu Pro)Upgrade libswscale-ffmpeg3 (Ubuntu Pro)Upgrade libavdevice-ffmpeg56 (Ubuntu Pro)Upgrade libpostproc-ffmpeg53 (Ubuntu Pro)Upgrade libavutil-ffmpeg54 (Ubuntu Pro)Upgrade ffmpeg (Ubuntu Pro)Upgrade libavresample-ffmpeg2 (Ubuntu Pro)Upgrade libavcodec-ffmpeg56 (Ubuntu Pro)Upgrade libavcodec-ffmpeg-extra56 (Ubuntu Pro)Upgrade libswresample-ffmpeg1 (Ubuntu Pro)Upgrade libavfilter-ffmpeg5 (Ubuntu Pro) | Mar 22, 2023 | Jun 2, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub