CVE-2021-38114: Medium severity FFmpeg FFmpeg vulnerability
Published Aug 4, 2021
·Updated
Last updated 24 July 2024
Other sources
libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of the initvlc function, a similar issue to CVE-2013-0868.
— Launchpad
Affected Software
5 affected componentsFixes available
debian/ffmpeg
7:4.3.7-0+deb11u17:4.3.8-0+deb11u17:5.1.6-0+deb12u17:7.0.2-37:7.1-3
FFmpeg FFmpeg=4.4
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ffmpegto a version that resolves this vulnerability.Fixed in 7:4.3.7-0+deb11u1Fixed in 7:4.3.8-0+deb11u1Fixed in 7:5.1.6-0+deb12u1Fixed in 7:7.0.2-3Fixed in 7:7.1-3
Event History
Aug 4, 2021
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:58 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:34 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38114.
2
What is the affected software?
The affected software is FFmpeg version 4.4.
3
What is the severity of CVE-2021-38114?
The severity of CVE-2021-38114 is not specified.
4
How does CVE-2021-38114 affect FFmpeg?
CVE-2021-38114 allows an attacker to execute arbitrary code by exploiting a vulnerability in the init_vlc function of the dnxhddec.c file in FFmpeg 4.4.
5
What is the recommended remedy for CVE-2021-38114?
The recommended remedy for CVE-2021-38114 is to update to FFmpeg version 4.4.2-0ubuntu0.21.10.1 or later.