FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavformat/aviobuf.c because dnn_backend_native.c calls ff_dnn_load_model_native and a certain index check is omitted.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ffmpeg4Upgrade ffmpeg | Aug 22, 2024 | Jun 16, 2020 |
| Debian | — | Upgrade ffmpeg | Jul 30, 2024 | Jun 16, 2020 |
| Ffmpeg | — | Upgrade to FFmpeg version 4.4Upgrade to FFmpeg version 4.3.1 | Jun 24, 2020 | Jun 16, 2020 |
| Gentoo Linux | — | Upgrade media-video/ffmpeg. | Jul 29, 2020 | Jun 16, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub