CVE-2020-22022: Buffer Overflow
Published May 27, 2021
·Updated
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filterframe at libavfilter/vffieldorder.c, which might lead to memory corruption and other potential consequences.
Affected Software
4 affected componentsFixes available
debian/ffmpeg
7:4.3.7-0+deb11u17:4.3.8-0+deb11u17:5.1.6-0+deb12u17:7.0.2-37:7.1-3
FFmpeg FFmpeg=4.2
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Remediation
Event History
May 27, 2021
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:45 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:24 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-22022?
CVE-2020-22022 is a heap-based Buffer Overflow vulnerability in FFmpeg 4.2.
2
What is the impact of CVE-2020-22022?
The vulnerability can lead to memory corruption and other potential consequences.
3
Which software versions are affected by CVE-2020-22022?
FFmpeg 4.2 is affected by CVE-2020-22022.
4
How can I fix CVE-2020-22022 on Ubuntu?
Upgrade to FFmpeg version 7:2.8.17-0ubuntu0.1+ or newer.
5
How can I fix CVE-2020-22022 on Debian?
Upgrade to FFmpeg version 7:4.1.9-0+deb10u1, 7:4.1.11-0+deb10u1, 7:4.3.6-0+deb11u1, 7:5.1.3-1, or 7:6.0-7.