CVE-2021-38093: Integer Overflow
Integer Overflow vulnerability in function filterrobert in libavfilter/vfconvolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/ffmpegto a version that resolves this vulnerability.Fixed in 7:4.2.7-0ubuntu0.1+ - Upgrade
Upgrade
debian/ffmpegto a version that resolves this vulnerability.Fixed in 7:4.3.6-0+deb11u1Fixed in 7:5.1.4-0+deb12u1Fixed in 7:6.1.1-1
Event History
Frequently Asked Questions
What is CVE-2021-38093?
CVE-2021-38093 is an Integer Overflow vulnerability in the filter_robert function in libavfilter/vf_convolution.c in Ffmpeg. It allows attackers to cause a Denial of Service or other unspecified impacts.
How severe is CVE-2021-38093?
CVE-2021-38093 has a severity score of 8.8 (high).
Which software versions are affected by CVE-2021-38093?
Ffmpeg version 4.2.1 is affected by CVE-2021-38093.
How can CVE-2021-38093 be fixed?
To fix CVE-2021-38093, it is recommended to update Ffmpeg to version 4.2.7-0ubuntu0.1+ (for Ubuntu) or 7:4.3.6-0+deb11u1, 7:5.1.3-1, or 7:6.0-7 (for Debian).
Where can I find more information about CVE-2021-38093?
More information about CVE-2021-38093 can be found at the following references: [Git commit](https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/99f8d32129dd233d4eb2efa44678a0bc44869f23), [FFmpeg ticket](https://trac.ffmpeg.org/ticket/8263), [CVE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38093).