CVE-2020-22019: Buffer Overflow
Published May 26, 2021
·Updated
Buffer Overflow vulnerability in FFmpeg 4.2 at convolutiony10bit in libavfilter/vfvmafmotion.c, which could let a remote malicious user cause a Denial of Service.
Affected Software
3 affected componentsFixes available
debian/ffmpeg
7:4.3.7-0+deb11u17:4.3.8-0+deb11u17:5.1.6-0+deb12u17:7.0.2-37:7.1-3
FFmpeg FFmpeg=4.2
Debian Debian Linux=10.0
Remediation
Event History
May 26, 2021
CVE Published
via MITRE·07:13 PM
Data Sourced
via MITRE·07:13 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:45 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:24 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-22019.
2
What is the title of the vulnerability?
The title of the vulnerability is Buffer Overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilter/vf_vmafmotion.c.
3
What is the description of the vulnerability?
The vulnerability is a buffer overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilter/vf_vmafmotion.c, which could let a remote malicious user cause a Denial of Service.
4
Which software is affected by this vulnerability?
FFmpeg 4.2 is affected by this vulnerability.
5
How can I fix the vulnerability?
To fix the vulnerability, you should update FFmpeg to version 4.4.1 or higher.