dwa_uncompress in libavcodec/exr.c in FFmpeg 4.4 allows an out-of-bounds array access because dc_count is not strictly checked.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ffmpegUpgrade ffmpeg4 | Aug 22, 2024 | Jun 3, 2021 |
| Ffmpeg | — | Upgrade to FFmpeg version 4.4 | Jun 9, 2021 | Jun 3, 2021 |
| Gentoo Linux | — | Upgrade media-video/ffmpeg. | Dec 27, 2023 | Jun 3, 2021 |
| Suse | — | Upgrade libavdevice58_13Upgrade libavcodec58_134Upgrade libavfilter7_110Upgrade libavformat58_76Upgrade libavutil56_70Upgrade libswscale5_9Upgrade libswresample3_9Upgrade libavresample4_0Upgrade libpostproc55_9 | Oct 26, 2022 | Jun 3, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub