CVE-2020-36138: Null Pointer Dereference
Published Aug 11, 2023
·Updated
An issue was discovered in decodeframe in libavcodec/tiff.c in FFmpeg version 4.3, allows remote attackers to cause a denial of service (DoS).
Affected Software
1 affected component
FFmpeg FFmpeg=4.3
Remediation
Patch Available
Event History
Aug 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-36138.
2
What is the severity rating of CVE-2020-36138?
CVE-2020-36138 has a severity rating of 7.5 (high).
3
How does CVE-2020-36138 affect FFmpeg?
CVE-2020-36138 affects FFmpeg version 4.3.
4
What is the impact of CVE-2020-36138?
CVE-2020-36138 allows remote attackers to cause a denial of service (DoS) in FFmpeg.
5
Are there any references for CVE-2020-36138?
Yes, you can refer to the following links for more information: [Link 1](https://github.com/FFmpeg/FFmpeg/commit/292e41ce650a7b5ca5de4ae87fff0d6a90d9fc97), [Link 2](https://lists.ffmpeg.org/pipermail/ffmpeg-devel/2020-November/272001.html), [Link 3](https://trac.ffmpeg.org/ticket/8960).