CVE-2020-22017: Buffer Overflow
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at fffillrectangle in libavfilter/drawutils.c, which might lead to memory corruption and other potential consequences.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-22017?
CVE-2020-22017 is a heap-based Buffer Overflow vulnerability in FFmpeg 4.2.
What is the impact of CVE-2020-22017?
The vulnerability could lead to memory corruption and other potential consequences.
Which software versions are affected by CVE-2020-22017?
FFmpeg 4.2 is affected. Specifically, versions 7:3.4.11-0ubuntu0.1, 7:4.2.7-0ubuntu0.1, and 4.3 are affected.
How can I fix CVE-2020-22017?
For Ubuntu, apply the remedies 7:3.4.11-0ubuntu0.1 or 7:4.2.7-0ubuntu0.1. For other affected versions, an upstream remedy of version 4.3 is available. Debian provides remedies such as 7:4.1.9-0+deb10u1, 7:4.1.11-0+deb10u1, 7:4.3.6-0+deb11u1, 7:5.1.3-1, and 7:6.0-7.
Where can I find more information about CVE-2020-22017?
You can find more information about CVE-2020-22017 at the following references: [CVE description](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-22017), [FFmpeg ticket](https://trac.ffmpeg.org/ticket/8309), [Ubuntu security notice](https://ubuntu.com/security/notices/USN-5472-1).