Your submission was sent successfully! Close

CVE-2020-20446

Published: 25 May 2021

FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aacpsy.c, which allows a remote malicious user to cause a Denial of Service.

Priority

Low

CVSS 3 base score: 6.5

Status

Package Release Status
ffmpeg
Launchpad, Ubuntu, Debian
bionic
Released (7:3.4.11-0ubuntu0.1)
focal
Released (7:4.2.7-0ubuntu0.1)
groovy Ignored
(reached end-of-life)
hirsute Ignored
(reached end-of-life)
impish
Released (7:4.4.2-0ubuntu0.21.10.1)
jammy Not vulnerable
(7:4.4.1-3ubuntu2)
trusty Does not exist

upstream
Released (4.4.1)
xenial Ignored
(out of standard support, was needed)
Patches:
upstream: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/223b5e8ac9f6461bb13ed365419ec485c5b2b002