First published: Sun Jan 03 2021(Updated: )
track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | =4.3.1 | |
Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35964 is classified as a high severity vulnerability due to the potential for out-of-bounds writes.
To fix CVE-2020-35964, you should upgrade FFmpeg to version 4.3.2 or later, which contains the necessary patches.
CVE-2020-35964 affects FFmpeg version 4.3.1 specifically.
CVE-2020-35964 involves an out-of-bounds write caused by incorrect extradata packing in the track_header function.
Yes, CVE-2020-35964 could potentially be exploited remotely if an attacker can manipulate media files processed by the affected FFmpeg version.