CVE-2021-28429: Integer Overflow
Published Aug 11, 2023
·Updated
Integer overflow vulnerability in avtimecodemakestring in libavutil/timecode.c in FFmpeg version 4.3.2, allows local attackers to cause a denial of service (DoS) via crafted .mov file.
Affected Software
2 affected componentsFixes available
debian/ffmpeg
7:4.3.7-0+deb11u17:4.3.8-0+deb11u17:5.1.6-0+deb12u17:7.0.2-37:7.1-3
FFmpeg FFmpeg=4.3.2
Remediation
Event History
Aug 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:54 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:17 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-28429.
2
What is the title of this vulnerability?
The title of this vulnerability is "Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version …".
3
What is the description of this vulnerability?
The description of this vulnerability is "Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local attackers to cause a denial of service (DoS) via crafted .mov file."
4
What software is affected by this vulnerability?
The software affected by this vulnerability is FFmpeg version 4.3.2.
5
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 5.5.