CVE-2020-22042: Medium severity ffmpeg vulnerability
Published Jun 1, 2021
·Updated
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak is affected by: memory leak in the linkfilterinouts function in libavfilter/graphparser.c.
Affected Software
3 affected componentsFixes available
debian/ffmpeg
7:4.3.7-0+deb11u17:4.3.8-0+deb11u17:5.1.6-0+deb12u17:7.0.2-37:7.1-3
FFmpeg FFmpeg=4.2
Debian Debian Linux=11.0
Remediation
Event History
Jun 1, 2021
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:45 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:25 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-22042?
CVE-2020-22042 is a Denial of Service (DoS) vulnerability that exists in FFmpeg 4.2 due to a memory leak in the link_filter_inouts function in libavfilter/graphparser.c.
2
How does CVE-2020-22042 affect FFmpeg?
CVE-2020-22042 affects FFmpeg version 4.2 and earlier.
3
What is the severity of CVE-2020-22042?
The severity of CVE-2020-22042 is moderate.
4
How can I fix CVE-2020-22042?
To fix CVE-2020-22042, update FFmpeg to version 4.2.7 or later.
5
Where can I find more information about CVE-2020-22042?
You can find more information about CVE-2020-22042 on the CVE website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-22042) and the FFmpeg trac ticket (https://trac.ffmpeg.org/ticket/8267).