CVE-2021-38091: Integer Overflow
Integer Overflow vulnerability in function filter16sobel in libavfilter/vfconvolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/ffmpegto a version that resolves this vulnerability.Fixed in 7:4.2.7-0ubuntu0.1+ - Upgrade
Upgrade
debian/ffmpegto a version that resolves this vulnerability.Fixed in 7:4.3.6-0+deb11u1Fixed in 7:5.1.4-0+deb12u1Fixed in 7:6.1.1-1
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38091.
What is the severity level of CVE-2021-38091?
The severity level of CVE-2021-38091 is high (8.8).
How can this vulnerability be exploited?
This vulnerability can be exploited by attackers to cause a Denial of Service or other unspecified impacts.
Which software versions are affected by CVE-2021-38091?
Ffmpeg 4.2.1 is affected by CVE-2021-38091.
Are there any fixes or patches available for this vulnerability?
Fixes or patches are available for Ffmpeg version 7:4.2.7-0ubuntu0.1+ (Ubuntu), version 7:4.3.6-0+deb11u1, 7:5.1.3-1, and 7:6.0-7 (Debian).