CVE-2020-22016: Buffer Overflow
Published May 27, 2021
·Updated
A heap-based Buffer Overflow vulnerability in FFmpeg 4.2 at libavcodec/getbits.h when writing .mov files, which might lead to memory corruption and other potential consequences.
Affected Software
4 affected componentsFixes available
debian/ffmpeg
7:4.3.7-0+deb11u17:4.3.8-0+deb11u17:5.1.6-0+deb12u17:7.0.2-37:7.1-3
FFmpeg FFmpeg=4.2
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Remediation
Event History
May 27, 2021
CVE Published
via MITRE·06:29 PM
Data Sourced
via MITRE·06:29 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:45 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:24 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-22016?
CVE-2020-22016 is a heap-based buffer overflow vulnerability in FFmpeg 4.2 at libavcodec/get_bits.h when writing .mov files.
2
How does CVE-2020-22016 affect software?
CVE-2020-22016 affects the ffmpeg package in various versions of Ubuntu and Debian.
3
What are the potential consequences of CVE-2020-22016?
CVE-2020-22016 may lead to memory corruption and other potential consequences.
4
How can I fix CVE-2020-22016 in Ubuntu?
To fix CVE-2020-22016 in Ubuntu, update the ffmpeg package to version 7:4.2.4-1ubuntu0.1.
5
How can I fix CVE-2020-22016 in Debian?
To fix CVE-2020-22016 in Debian, update the ffmpeg package to one of the following versions: 7:4.1.9-0+deb10u1, 7:4.1.11-0+deb10u1, 7:4.3.6-0+deb11u1, 7:5.1.3-1, 7:6.0-7.