CVE-2020-22015: Buffer Overflow
Buffer Overflow vulnerability in FFmpeg 4.2 in movwritevideotag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-22015?
CVE-2020-22015 is a buffer overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c.
What is the impact of CVE-2020-22015?
The impact of CVE-2020-22015 includes the potential for a remote malicious user to obtain sensitive information, cause a Denial of Service, or execute arbitrary code.
Which software versions are affected by CVE-2020-22015?
FFmpeg versions up to and including 4.4.1, 7:3.4.11-0ubuntu0.1, 7:4.2.7-0ubuntu0.1, 7:4.4.2-0ubuntu0.21.10.1, and 7:4.1.9-0+deb10u1, 7:4.1.11-0+deb10u1, 7:4.3.6-0+deb11u1, 7:5.1.3-1, 7:6.0-7 are affected by CVE-2020-22015.
How can I verify if I am using an affected version of FFmpeg?
You can check your FFmpeg version by running 'ffmpeg -version' command in the terminal.
How do I fix CVE-2020-22015?
To fix CVE-2020-22015, you should update FFmpeg to version 4.4.1 or later, or apply the available security patches for your specific distribution.