CVE-2021-38094: Integer Overflow
Integer Overflow vulnerability in function filtersobel in libavfilter/vfconvolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/ffmpegto a version that resolves this vulnerability.Fixed in 7:4.2.7-0ubuntu0.1+ - Upgrade
Upgrade
debian/ffmpegto a version that resolves this vulnerability.Fixed in 7:4.3.6-0+deb11u1Fixed in 7:5.1.4-0+deb12u1Fixed in 7:6.1.1-1
Event History
Frequently Asked Questions
What is CVE-2021-38094?
CVE-2021-38094 is an Integer Overflow vulnerability in the filter_sobel function in libavfilter/vf_convolution.c in Ffmpeg 4.2.1.
What is the severity of CVE-2021-38094?
The severity of CVE-2021-38094 is high with a CVSS score of 8.8.
What is the affected software for CVE-2021-38094?
The affected software includes Ffmpeg 4.2.1 and Ubuntu 7:4.2.7-0ubuntu0.1+.
How can an attacker exploit CVE-2021-38094?
An attacker can exploit CVE-2021-38094 to cause a Denial of Service or other unspecified impacts.
Are there any references for CVE-2021-38094?
Yes, you can find references for CVE-2021-38094 at the following links: [Reference 1](https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/99f8d32129dd233d4eb2efa44678a0bc44869f23), [Reference 2](https://trac.ffmpeg.org/ticket/8263), [Reference 3](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38094).