A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ffmpeg | Nov 29, 2021 | Jun 2, 2021 |
| Ffmpeg | — | Upgrade to FFmpeg version 4.3 | Jun 9, 2021 | Jun 2, 2021 |
| Suse | — | Upgrade libavutil55Upgrade libavcodec57Upgrade libavformat57-32bitUpgrade libswresample2-32bitUpgrade libavdevice57Upgrade libavresample3-32bitUpgrade libswresample-develUpgrade libavdevice57-32bitUpgrade libpostproc54Upgrade libavfilter6-32bitUpgrade libswscale-develUpgrade libavformat-develUpgrade libavfilter-develUpgrade libpostproc54-32bitUpgrade libavutil55-32bitUpgrade libavdevice-develUpgrade libavutil-develUpgrade ffmpegUpgrade libswscale4Upgrade libavresample-develUpgrade libavformat57Upgrade libavresample3-64bitUpgrade libavcodec57-32bitUpgrade libswresample2Upgrade libavresample3Upgrade libavfilter6Upgrade libswscale4-32bitUpgrade libpostproc-develUpgrade libavcodec-develUpgrade ffmpeg-private-devel | Sep 3, 2021 | Jun 2, 2021 |
| Ubuntu | — | Upgrade libavutil-ffmpeg54 (Ubuntu Pro)Upgrade libavcodec-extra (Ubuntu Pro)Upgrade libavformat-ffmpeg56 (Ubuntu Pro)Upgrade libpostproc-ffmpeg53 (Ubuntu Pro)Upgrade ffmpeg (Ubuntu Pro)Upgrade libswresample-ffmpeg1 (Ubuntu Pro)Upgrade libavfilter-ffmpeg5 (Ubuntu Pro)Upgrade libswscale-ffmpeg3 (Ubuntu Pro)Upgrade libavcodec-ffmpeg-extra56 (Ubuntu Pro)Upgrade libavresample-ffmpeg2 (Ubuntu Pro)Upgrade libavcodec-ffmpeg56 (Ubuntu Pro)Upgrade libavdevice-ffmpeg56 (Ubuntu Pro) | Mar 22, 2023 | Jun 2, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub