CVE-2020-22036: Buffer Overflow
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filterintra at libavfilter/vfbwdif.c, which might lead to memory corruption and other potential consequences.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-22036?
CVE-2020-22036 is a heap-based Buffer Overflow vulnerability in FFmpeg 4.2 in filter_intra at libavfilter/vf_bwdif.c.
What are the potential consequences of CVE-2020-22036?
CVE-2020-22036 can lead to memory corruption and other potential consequences.
Which software is affected by CVE-2020-22036?
FFmpeg versions 3.4.11-0ubuntu0.1, 4.2.7-0ubuntu0.1, and 4.3 are affected. Debian versions 4.1.9-0+deb10u1, 4.1.11-0+deb10u1, 4.3.6-0+deb11u1, 5.1.3-1, and 6.0-7 are also affected.
How can I fix CVE-2020-22036 on Ubuntu?
Upgrade FFmpeg to version 3.4.11-0ubuntu0.1, 4.2.7-0ubuntu0.1, or 4.3, depending on your distribution.
How can I fix CVE-2020-22036 on Debian?
Upgrade FFmpeg to version 4.1.9-0+deb10u1, 4.1.11-0+deb10u1, 4.3.6-0+deb11u1, 5.1.3-1, or 6.0-7, depending on your distribution.