First published: Wed Jun 02 2021(Updated: )
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg FFmpeg | =4.2 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-22048 is a Denial of Service vulnerability in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c.
CVE-2020-22048 has a severity rating of medium, with a severity value of 6.5.
FFmpeg 4.2 and Debian Linux 9.0 are affected by CVE-2020-22048.
Update FFmpeg to a version that fixes the vulnerability, and follow any recommendations provided by the vendor or project.
Yes, you can find more information about CVE-2020-22048 in the following references: - [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2021/11/msg00012.html) - [FFmpeg Ticket](https://trac.ffmpeg.org/ticket/8303)