CVE-2021-38291: High severity FFmpeg FFmpeg vulnerability
FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ffmpegto a version that resolves this vulnerability.Fixed in 7:4.3.7-0+deb11u1Fixed in 7:4.3.8-0+deb11u1Fixed in 7:5.1.6-0+deb12u1Fixed in 7:7.0.2-3Fixed in 7:7.1-3
Event History
Frequently Asked Questions
What is CVE-2021-38291?
CVE-2021-38291 is a vulnerability in FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) that suffers from an assertion failure at src/libavutil/mathematics.c.
Which software is affected by CVE-2021-38291?
FFmpeg versions 7:4.4.2-0ubuntu0.21.10.1, 7:2.8.17-0ubuntu0.1+, 7:3.4.11-0ubuntu0.1, 7:4.2.7-0ubuntu0.1, and 4.4.1 are affected by CVE-2021-38291.
How severe is CVE-2021-38291?
The severity of CVE-2021-38291 is not specified in the information provided.
How can I fix CVE-2021-38291?
To fix CVE-2021-38291, you should update FFmpeg to a version that includes the necessary fix. Refer to the official documentation or the vendor's security notice for specific instructions.
Where can I find more information about CVE-2021-38291?
You can find more information about CVE-2021-38291 on the CVE website and the official security notices from Ubuntu.