CVE-2020-21697: Use After Free
Published Aug 10, 2021
·Updated
A heap-use-after-free in the mpegmuxwritepacket function in libavformat/mpegenc.c of FFmpeg 4.2 allows to cause a denial of service (DOS) via a crafted avi file.
Affected Software
3 affected componentsFixes available
debian/ffmpeg
7:4.3.7-0+deb11u17:4.3.8-0+deb11u17:5.1.6-0+deb12u17:7.0.2-37:7.1-3
FFmpeg FFmpeg=4.2
Debian Debian Linux=11.0
Remediation
Patch Available
Event History
Aug 10, 2021
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:44 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:24 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-21697?
CVE-2020-21697 is a vulnerability in FFmpeg 4.2 that allows a denial of service (DOS) through a crafted avi file.
2
How does CVE-2020-21697 affect the affected software?
CVE-2020-21697 affects the FFmpeg packages in various versions of Ubuntu and Debian.
3
How can I fix CVE-2020-21697?
To fix CVE-2020-21697, update the FFmpeg packages to the recommended versions provided by Ubuntu or Debian.
4
Where can I find more information about CVE-2020-21697?
You can find more information about CVE-2020-21697 on the MITRE CVE website, FFmpeg trac ticket, and Ubuntu security notices.
5
What CWE category does CVE-2020-21697 belong to?
CVE-2020-21697 belongs to CWE category 416 - Use After Free.