Your submission was sent successfully! Close

CVE-2020-21041

Published: 24 May 2021

Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a remote malicious user cause a Denial of Service

Priority

Medium

CVSS 3 base score: 7.5

Status

Package Release Status
ffmpeg
Launchpad, Ubuntu, Debian
bionic
Released (7:3.4.11-0ubuntu0.1)
focal
Released (7:4.2.7-0ubuntu0.1)
groovy Ignored
(reached end-of-life)
hirsute Ignored
(reached end-of-life)
impish
Released (7:4.4-6ubuntu5)
jammy Not vulnerable

trusty Does not exist

upstream
Released (4.4)
xenial Ignored
(out of standard support)
Patches:
upstream: https://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=5d9f44da460f781a1604d537d0555b78e29438ba