CVE-2021-38090: Integer Overflow
Integer Overflow vulnerability in function filter16roberts in libavfilter/vfconvolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/ffmpegto a version that resolves this vulnerability.Fixed in 7:4.2.7-0ubuntu0.1+ - Upgrade
Upgrade
debian/ffmpegto a version that resolves this vulnerability.Fixed in 7:4.3.6-0+deb11u1Fixed in 7:5.1.4-0+deb12u1Fixed in 7:6.1.1-1
Event History
Frequently Asked Questions
What is CVE-2021-38090?
CVE-2021-38090 is an integer overflow vulnerability in the function filter16_roberts in libavfilter/vf_convolution.c in Ffmpeg 4.2.1.
What are the potential impacts of CVE-2021-38090?
The potential impacts of CVE-2021-38090 include Denial of Service or other unspecified impacts.
What is the severity of CVE-2021-38090?
The severity of CVE-2021-38090 is high, with a severity score of 8.8.
Which software versions are affected by CVE-2021-38090?
Ffmpeg 4.2.1 is affected by CVE-2021-38090.
How can CVE-2021-38090 be fixed?
To fix CVE-2021-38090, it is recommended to update to a patched version of Ffmpeg.