CVE-2020-21041

Name
CVE-2020-21041
Description
Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a remote malicious user cause a Denial of Service
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://trac.ffmpeg.org/ticket/7989
Mailing List https://lists.debian.org/debian-lts-announce/2021/08/msg00018.html
DEBIAN https://www.debian.org/security/2021/dsa-4990

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:ffmpeg:ffmpeg:4.1:*:*:*:*:*:*:* ffmpeg == None == 4.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ffmpeg5 edge-community 4.4-r0 None fixed
ffmpeg4 edge-community 4.4-r0 None fixed
ffmpeg4 3.22-community 4.4-r0 None fixed
ffmpeg4 3.21-community 4.4-r0 None fixed
ffmpeg4 3.20-community 4.4-r0 None fixed
ffmpeg4 3.19-community 4.4-r0 None fixed
ffmpeg4 3.18-community 4.4-r0 None fixed
ffmpeg4 3.17-community 4.4-r0 None fixed
ffmpeg edge-community 4.4-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
ffmpeg edge-community 4.1-r0 None possibly vulnerable
ffmpeg 3.22-community 4.4-r0 None fixed
ffmpeg 3.22-community 4.1-r0 None possibly vulnerable
ffmpeg 3.21-community 4.4-r0 None fixed
ffmpeg 3.20-community 4.4-r0 None fixed
ffmpeg 3.19-community 4.4-r0 None fixed
ffmpeg 3.18-community 4.4-r0 None fixed
ffmpeg 3.17-community 4.4-r0 None fixed