A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ffmpeg | Nov 29, 2021 | Jun 2, 2021 |
| Ffmpeg | — | Upgrade to FFmpeg version 4.3 | Jun 9, 2021 | Jun 2, 2021 |
| Suse | — | Upgrade libswscale-develUpgrade ffmpegUpgrade libavfilter-develUpgrade libavresample-develUpgrade libavdevice57-32bitUpgrade ffmpeg-private-develUpgrade libavdevice-develUpgrade libswscale4-32bitUpgrade libavutil55Upgrade libavformat-develUpgrade libavresample3Upgrade libavutil55-32bitUpgrade libswscale4Upgrade libavformat57Upgrade libavcodec57Upgrade libavdevice57Upgrade libavresample3-32bitUpgrade libswresample2Upgrade libswresample2-32bitUpgrade libpostproc54-32bitUpgrade libavfilter6Upgrade libavformat57-32bitUpgrade libpostproc54Upgrade libavfilter6-32bitUpgrade libavcodec57-32bitUpgrade libavcodec-develUpgrade libswresample-develUpgrade libavresample3-64bitUpgrade libpostproc-develUpgrade libavutil-devel | Sep 3, 2021 | Jun 2, 2021 |
| Ubuntu | — | Upgrade libavfilter-ffmpeg5 (Ubuntu Pro)Upgrade libswresample-ffmpeg1 (Ubuntu Pro)Upgrade libavcodec-ffmpeg-extra56 (Ubuntu Pro)Upgrade libavutil-ffmpeg54 (Ubuntu Pro)Upgrade libavcodec-ffmpeg56 (Ubuntu Pro)Upgrade ffmpeg (Ubuntu Pro)Upgrade libavresample-ffmpeg2 (Ubuntu Pro)Upgrade libavdevice-ffmpeg56 (Ubuntu Pro)Upgrade libavformat-ffmpeg56 (Ubuntu Pro)Upgrade libswscale-ffmpeg3 (Ubuntu Pro)Upgrade libpostproc-ffmpeg53 (Ubuntu Pro)Upgrade libavcodec-extra (Ubuntu Pro) | Mar 22, 2023 | Jun 2, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub