CVE-2020-22026: Buffer Overflow
Buffer Overflow vulnerability exists in FFmpeg 4.2 in the configinput function at libavfilter/aftremolo.c, which could let a remote malicious user cause a Denial of Service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-22026?
CVE-2020-22026 is a Buffer Overflow vulnerability in FFmpeg 4.2.
How does the Buffer Overflow vulnerability in FFmpeg 4.2 work?
The Buffer Overflow vulnerability exists in the config_input function at libavfilter/af_tremolo.c in FFmpeg 4.2, which could be exploited by a remote malicious user to cause a Denial of Service.
Which software versions are affected by CVE-2020-22026?
The affected software versions include FFmpeg 4.2 and 7:3.4.11-0ubuntu0.1, 7:4.2.7-0ubuntu0.1, 4.3, 7:4.1.9-0+deb10u1, 7:4.1.11-0+deb10u1, 7:4.3.6-0+deb11u1, 7:5.1.3-1, and 7:6.0-7.
How can I fix the Buffer Overflow vulnerability in FFmpeg 4.2?
To fix the vulnerability, update FFmpeg to version 7:3.4.11-0ubuntu0.1 or higher.
Where can I find more information about CVE-2020-22026?
You can find more information about CVE-2020-22026 on the MITRE CVE website, the FFmpeg ticket tracker, and the Ubuntu security notices.