First published: Tue Jun 16 2020(Updated: )
FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavformat/aviobuf.c because dnn_backend_native.c calls ff_dnn_load_model_native and a certain index check is omitted.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | >=4.3<4.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14212 has a medium severity due to the potential for a heap-based buffer overflow leading to denial of service or code execution.
To fix CVE-2020-14212, upgrade FFmpeg to version 4.3.1 or later where the vulnerability is addressed.
CVE-2020-14212 affects FFmpeg versions up to and including 4.3.
The potential impacts of CVE-2020-14212 include application crashes and possible remote code execution, depending on the usage context.
There are no known workarounds for CVE-2020-14212, making upgrading the best mitigation strategy.