CVE-2020-26797: Buffer Overflow
Published Mar 18, 2021
·Updated
Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::FileGxf::ChooseParserChannelGrouping.
Affected Software
2 affected components
MediaArea MediaInfo<20.08
Fedoraproject Fedora=33
Remediation
Patch Available
Event History
Mar 18, 2021
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
Description
Frequently Asked Questions
1
What is CVE-2020-26797?
CVE-2020-26797 is a heap buffer overflow vulnerability in Mediainfo before version 20.08.
2
How does the vulnerability occur?
The vulnerability occurs due to a heap buffer overflow in the MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping function.
3
What is the severity of CVE-2020-26797?
The severity of CVE-2020-26797 is high, with a severity value of 7.5.
4
What software versions are affected by CVE-2020-26797?
Mediainfo versions before 20.08 are affected by CVE-2020-26797.
5
How can I fix CVE-2020-26797?
To fix CVE-2020-26797, it is recommended to update to version 20.08 or later of Mediainfo.