CVE-2020-22033: Buffer Overflow
A heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vfvmafmotion.c in convolutiony8bit, which could let a remote malicious user cause a Denial of Service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-22033?
CVE-2020-22033 is a heap-based buffer overflow vulnerability in FFmpeg 4.2 at libavfilter/vf_vmafmotion.c.
How does CVE-2020-22033 impact the system?
CVE-2020-22033 could allow a remote malicious user to cause a denial of service (DoS) on the system.
Which software versions are affected by CVE-2020-22033?
The affected software versions include FFmpeg 4.4.2-0ubuntu0.21.10.1, 3.4.11-0ubuntu0.1, 4.2.7-0ubuntu0.1, and 4.4.1.
How can I fix CVE-2020-22033 on Ubuntu?
To fix CVE-2020-22033 on Ubuntu, you should update FFmpeg to version 4.4.2-0ubuntu0.21.10.1, 3.4.11-0ubuntu0.1, or 4.2.7-0ubuntu0.1.
Where can I find more information about CVE-2020-22033?
You can find more information about CVE-2020-22033 on the CVE website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-22033), the FFmpeg trac ticket (https://trac.ffmpeg.org/ticket/8246), and the Ubuntu Security Notice USN-5472-1 (https://ubuntu.com/security/notices/USN-5472-1).