CVE-2020-35965Out-of-bounds Write in Ffmpeg

Severity
7.5HIGHNVD
OSV6.5
EPSS
1.6%
top 18.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 4
Latest updateJun 13

Description

decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDffmpeg/ffmpeg4.3.14.4
debiandebian/ffmpeg< ffmpeg 7:4.3.1-6 (bookworm)
Debianffmpeg/ffmpeg< 7:4.3.1-6+3
Ubuntuffmpeg/ffmpeg< 7:3.4.11-0ubuntu0.1+3

Also affects: Debian Linux 10.0, 9.0

Patches

🔴Vulnerability Details

4
OSV
ffmpeg vulnerabilities2022-06-13
OSV
ffmpeg vulnerabilities2022-06-08
GHSA
GHSA-cpq4-98gj-fhjv: decode_frame in libavcodec/exr2022-05-24
OSV
CVE-2020-35965: decode_frame in libavcodec/exr2021-01-04

📋Vendor Advisories

3
Ubuntu
FFmpeg vulnerabilities2022-06-13
Ubuntu
FFmpeg vulnerabilities2022-06-08
Debian
CVE-2020-35965: ffmpeg - decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write beca...2020