CVE-2021-38092: Integer Overflow
Integer Overflow vulnerability in function filterprewitt in libavfilter/vfconvolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ffmpegto a version that resolves this vulnerability.Fixed in 7:4.3.6-0+deb11u1Fixed in 7:5.1.4-0+deb12u1Fixed in 7:6.1.1-1 - Upgrade
Upgrade
ubuntu/ffmpegto a version that resolves this vulnerability.Fixed in 7:4.2.7-0ubuntu0.1+
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38092.
What component of Ffmpeg is affected by this vulnerability?
The function filter_prewitt in libavfilter/vf_convolution.c is affected by this vulnerability.
What is the severity of CVE-2021-38092?
The severity of CVE-2021-38092 is high, with a CVSS score of 8.8.
What are the possible impacts of this vulnerability?
This vulnerability can cause a Denial of Service or other unspecified impacts.
How can I fix this vulnerability in Ffmpeg 4.2.1?
To fix this vulnerability, upgrade Ffmpeg to version 7:4.2.7-0ubuntu0.1+ or higher.
Are there any additional references for CVE-2021-38092?
Yes, you can refer to these sources for more information: [Git Commit](https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/99f8d32129dd233d4eb2efa44678a0bc44869f23), [FFmpeg Ticket](https://trac.ffmpeg.org/ticket/8263), and [CVE Details](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38092).