CVE-2020-22037: Medium severity ffmpeg vulnerability
Published Jun 1, 2021
·Updated
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodecalloccontext3 at options.c.
Affected Software
5 affected componentsFixes available
debian/ffmpeg
7:4.3.7-0+deb11u17:4.3.8-0+deb11u17:5.1.6-0+deb12u17:7.0.2-37:7.1-3
FFmpeg FFmpeg=4.2
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Patch Available
Event History
Jun 1, 2021
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:45 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:25 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-22037?
CVE-2020-22037 is a Denial of Service vulnerability in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.
2
How does the vulnerability in FFmpeg 4.2 affect me?
The vulnerability in FFmpeg 4.2 can be exploited to cause a Denial of Service attack, potentially affecting the availability of your system.
3
Which versions of FFmpeg are affected by CVE-2020-22037?
FFmpeg versions 4.2 are affected by CVE-2020-22037.
4
How do I fix the vulnerability in FFmpeg 4.2?
To fix the vulnerability, you should update your FFmpeg installation to version 4.4.1 or later.
5
Where can I find more information about CVE-2020-22037?
You can find more information about CVE-2020-22037 on the CVE website at [CVE-2020-22037](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-22037).