CVE-2021-38171: Critical severity FFmpeg FFmpeg vulnerability
adtsdecodeextradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the initgetbits return value, which is a necessary step because the second argument to initgetbits can be crafted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ffmpegto a version that resolves this vulnerability.Fixed in 7:4.3.7-0+deb11u1Fixed in 7:4.3.8-0+deb11u1Fixed in 7:5.1.6-0+deb12u1Fixed in 7:7.0.2-3Fixed in 7:7.1-3
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38171.
What is the affected software?
The affected software is FFmpeg 4.4.
What is the severity of CVE-2021-38171?
The severity of CVE-2021-38171 is not specified in the provided information.
How can I fix the vulnerability in FFmpeg 4.4?
To fix the vulnerability in FFmpeg 4.4, you can apply the official patch provided by FFmpeg or update to version 4.4.2-0ubuntu0.21.10.1.
Where can I find additional information about CVE-2021-38171?
You can find additional information about CVE-2021-38171 on the CVE Mitre website and the GitHub and Patchwork links provided.