First published: Mon Sep 20 2021(Updated: )
An issue was discovered in function latm_write_packet in libavformat/latmenc.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts due to a Null pointer dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg FFmpeg | =4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-20896 is a vulnerability in Ffmpeg 4.2.1 that allows attackers to cause a Denial of Service or other unspecified impacts due to a Null pointer dereference in the latm_write_packet function of libavformat/latmenc.c.
The severity of CVE-2020-20896 is high, with a severity value of 8.8 (out of 10).
This vulnerability can lead to a Denial of Service attack or other unspecified impacts on systems that use Ffmpeg 4.2.1.
Yes, there is a fix available. It is recommended to update Ffmpeg to a version that includes the fix.
You can find more information about CVE-2020-20896 in the references provided: [1](https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/dd01947397b98e94c3f2a79d5820aaf4594f4d3b) and [2](https://trac.ffmpeg.org/ticket/8273).