First published: Mon Sep 20 2021(Updated: )
Integer Overflow vulnerability in function filter16_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/ffmpeg | <=7:4.1.9-0+deb10u1<=7:4.1.11-0+deb10u1 | 7:4.3.6-0+deb11u1 7:5.1.4-0+deb12u1 7:6.1.1-1 |
ubuntu/ffmpeg | <7:4.2.7-0ubuntu0.1+ | 7:4.2.7-0ubuntu0.1+ |
ubuntu/ffmpeg | <7:4.3-2 | 7:4.3-2 |
FFmpeg FFmpeg | =4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-20898 is an integer overflow vulnerability in the function filter16_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1.
The severity of CVE-2020-20898 is high, with a severity value of 8.8.
CVE-2020-20898 can cause a Denial of Service or other unspecified impacts.
To mitigate CVE-2020-20898, update to the latest version of Ffmpeg or apply the relevant patches.
You can find more information about CVE-2020-20898 at the following references: [link1](https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/99f8d32129dd233d4eb2efa44678a0bc44869f23), [link2](https://trac.ffmpeg.org/ticket/8263), [link3](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20898).