Your submission was sent successfully! Close

CVE-2020-22015

Published: 26 May 2021

Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.

Priority

Medium

CVSS 3 base score: 8.8

Status

Package Release Status
ffmpeg
Launchpad, Ubuntu, Debian
bionic
Released (7:3.4.11-0ubuntu0.1)
focal
Released (7:4.2.7-0ubuntu0.1)
groovy Ignored
(reached end-of-life)
hirsute Ignored
(reached end-of-life)
impish
Released (7:4.4.2-0ubuntu0.21.10.1)
jammy Not vulnerable
(7:4.4.1-3ubuntu2)
trusty Does not exist

upstream
Released (4.4.1)
xenial Not vulnerable
(code not present)
Patches:
upstream: https://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=4c1afa292520329eecd1cc7631bc59a8cca95c46