CVE-2020-22023: Buffer Overflow
A heap-based Buffer Overflow vulnerabililty exists in FFmpeg 4.2 in filterframe at libavfilter/vfbitplanenoise.c, which might lead to memory corruption and other potential consequences.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this heap-based Buffer Overflow vulnerability?
The vulnerability ID is CVE-2020-22023.
Where does the heap-based Buffer Overflow vulnerability exist in FFmpeg 4.2?
The vulnerability exists in the filter_frame function at libavfilter/vf_bitplanenoise.c in FFmpeg 4.2.
What are the potential consequences of the heap-based Buffer Overflow vulnerability?
The potential consequences include memory corruption and other issues.
Which versions of FFmpeg are affected by this vulnerability?
FFmpeg versions 3.4.11-0ubuntu0.1, 4.2.7-0ubuntu0.1, 4.3, and various versions in the Debian repository are affected.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the following references: [CVE-2020-22023](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-22023), [FFmpeg Ticket #8244](https://trac.ffmpeg.org/ticket/8244), and [Ubuntu Security Notice USN-5472-1](https://ubuntu.com/security/notices/USN-5472-1).