CVE-2020-22035: Buffer Overflow
Published Jun 1, 2021
·Updated
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in getblockrow at libavfilter/vfbm3d.c, which might lead to memory corruption and other potential consequences.
Affected Software
3 affected componentsFixes available
debian/ffmpeg
7:4.3.7-0+deb11u17:4.3.8-0+deb11u17:5.1.6-0+deb12u17:7.0.2-37:7.1-3
FFmpeg FFmpeg=4.2
Debian Debian Linux=10.0
Remediation
Event History
Jun 1, 2021
CVE Published
via MITRE·06:31 PM
Data Sourced
via MITRE·06:31 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:45 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:25 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-22035?
CVE-2020-22035 is a heap-based Buffer Overflow vulnerability in FFmpeg 4.2.
2
Where does the vulnerability exist in FFmpeg 4.2?
The vulnerability exists in get_block_row at libavfilter/vf_bm3d.c in FFmpeg 4.2.
3
What are the potential consequences of CVE-2020-22035?
CVE-2020-22035 might lead to memory corruption and other potential consequences.
4
How can I check if my version of FFmpeg is affected?
You can check if your version of FFmpeg is affected by referring to the affected software section and the provided links.
5
How do I fix CVE-2020-22035?
To fix CVE-2020-22035, you should update to the recommended version of FFmpeg mentioned in the affected software section.