CVE-2020-21688: Use After Free
Published Aug 10, 2021
·Updated
A heap-use-after-free in the avfreep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary code.
Affected Software
3 affected componentsFixes available
debian/ffmpeg
7:4.3.7-0+deb11u17:4.3.8-0+deb11u17:5.1.6-0+deb12u17:7.0.2-37:7.1-3
FFmpeg FFmpeg=4.2
Debian Debian Linux=11.0
Remediation
Patch Available
Event History
Aug 10, 2021
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:44 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:24 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-21688?
CVE-2020-21688 is a heap-use-after-free vulnerability in the av_freep function of FFmpeg 4.2.
2
How does CVE-2020-21688 work?
CVE-2020-21688 works by allowing attackers to execute arbitrary code through a heap-use-after-free vulnerability in FFmpeg.
3
What software is affected by CVE-2020-21688?
FFmpeg versions 4.2.7-0ubuntu0.1, 2.8.17-0ubuntu0.1+, 3.4.11-0ubuntu0.1, 4.4, and various Debian versions are affected by CVE-2020-21688.
4
How can I fix CVE-2020-21688?
To fix CVE-2020-21688, update FFmpeg to version 4.2.7-0ubuntu0.1 or apply the appropriate patches from the vendor.
5
Where can I find more information about CVE-2020-21688?
You can find more information about CVE-2020-21688 on the CVE Mitre website, the FFmpeg ticket #8186, and the Ubuntu Security Notices page USN-5472-1.