CVE-2020-22027: Buffer Overflow
A heap-based Buffer Overflow vulnerability exits in FFmpeg 4.2 in deflate16 at libavfilter/vfneighbor.c, which might lead to memory corruption and other potential consequences.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-22027?
CVE-2020-22027 is a heap-based Buffer Overflow vulnerability that exists in FFmpeg 4.2 in deflate16 at libavfilter/vf_neighbor.c.
What are the potential consequences of CVE-2020-22027?
CVE-2020-22027 might lead to memory corruption and other potential consequences.
Which software versions are affected by CVE-2020-22027?
FFmpeg versions 4.2.7-0ubuntu0.1, 4.3, 4.1.9-0+deb10u1, 4.1.11-0+deb10u1, 4.3.6-0+deb11u1, 5.1.3-1, and 6.0-7 are affected by CVE-2020-22027.
How can I fix CVE-2020-22027?
To fix CVE-2020-22027, update FFmpeg to version 7:4.2.7-0ubuntu0.1 or apply the recommended fixes provided by Ubuntu or Debian.
Where can I find more information about CVE-2020-22027?
You can find more information about CVE-2020-22027 on the MITRE CVE website and the FFmpeg Trac ticket.