CVE-2020-20445: Divide by Zero
Published May 25, 2021
·Updated
FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/lpc.h, which allows a remote malicious user to cause a Denial of Service.
Affected Software
5 affected componentsFixes available
debian/ffmpeg
7:4.3.7-0+deb11u17:4.3.8-0+deb11u17:5.1.6-0+deb12u17:7.0.2-37:7.1-3
FFmpeg FFmpeg=4.2
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Patch Available
Event History
May 25, 2021
CVE Published
via MITRE·05:27 PM
Data Sourced
via MITRE·05:27 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:44 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:24 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-20445?
CVE-2020-20445 is a vulnerability in FFmpeg 4.2 that allows a remote malicious user to cause a Denial of Service through a Divide By Zero issue.
2
How does CVE-2020-20445 affect FFmpeg?
CVE-2020-20445 affects FFmpeg 4.2 through a Divide By Zero issue in libavcodec/lpc.h.
3
What is the severity of CVE-2020-20445?
The severity of CVE-2020-20445 is not mentioned in the provided information.
4
Which versions of FFmpeg are affected by CVE-2020-20445?
FFmpeg 4.2, 4.2.x, 3.4.11, 4.4.2, 4.4.x, 4.2.7, 4.1.9, 4.1.11, 4.3.6, 5.1.3, and 6.0-7 are affected by CVE-2020-20445.
5
How can I fix CVE-2020-20445?
Apply the latest security updates provided by Ubuntu or Debian for FFmpeg to fix CVE-2020-20445.