First published: Fri Aug 11 2023(Updated: )
An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4.3, allows remote attackers to cause a denial of service (DoS).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg FFmpeg | =4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2020-36138.
CVE-2020-36138 has a severity rating of 7.5 (high).
CVE-2020-36138 affects FFmpeg version 4.3.
CVE-2020-36138 allows remote attackers to cause a denial of service (DoS) in FFmpeg.
Yes, you can refer to the following links for more information: [Link 1](https://github.com/FFmpeg/FFmpeg/commit/292e41ce650a7b5ca5de4ae87fff0d6a90d9fc97), [Link 2](https://lists.ffmpeg.org/pipermail/ffmpeg-devel/2020-November/272001.html), [Link 3](https://trac.ffmpeg.org/ticket/8960).