CVE-2020-21041: Buffer Overflow
Published May 24, 2021
·Updated
Buffer Overflow vulnerability exists in FFmpeg 4.1 via apngdoinverseblend in libavcodec/pngenc.c, which could let a remote malicious user cause a Denial of Service
Affected Software
4 affected componentsFixes available
debian/ffmpeg
7:4.3.7-0+deb11u17:4.3.8-0+deb11u17:5.1.6-0+deb12u17:7.0.2-37:7.1-3
FFmpeg FFmpeg=4.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
May 24, 2021
CVE Published
via MITRE·05:31 PM
Data Sourced
via MITRE·05:31 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:44 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:24 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this buffer overflow vulnerability?
The vulnerability ID of this buffer overflow vulnerability is CVE-2020-21041.
2
In which version of FFmpeg does this vulnerability exist?
This vulnerability exists in FFmpeg version 4.1.
3
What is the root cause of this vulnerability?
The root cause of this vulnerability is a buffer overflow in the apng_do_inverse_blend function in libavcodec/pngenc.c.
4
What can a remote malicious user do with this vulnerability?
A remote malicious user can exploit this vulnerability to cause a Denial of Service (DoS) attack.
5
Are there any remedies available for this vulnerability?
Yes, there are remedies available for this vulnerability. Please refer to the provided references for more information.