CVE-2020-35964

Name
CVE-2020-35964
Description
track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://github.com/FFmpeg/FFmpeg/commit/27a99e2c7d450fef15594671eef4465c8a166bd7
Exploit https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26622
GENTOO https://security.gentoo.org/glsa/202105-24

Match rules

CPE URI Source package Min version Max version

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ffmpeg5 edge-community 4.3.2-r0 None fixed
ffmpeg4 edge-community 4.3.2-r0 None fixed
ffmpeg4 3.22-community 4.3.2-r0 None fixed
ffmpeg4 3.21-community 4.3.2-r0 None fixed
ffmpeg4 3.20-community 4.3.2-r0 None fixed
ffmpeg4 3.19-community 4.3.2-r0 None fixed
ffmpeg4 3.18-community 4.3.2-r0 None fixed
ffmpeg4 3.17-community 4.3.2-r0 None fixed
ffmpeg edge-community 4.3.2-r0 None fixed
ffmpeg 3.22-community 4.3.2-r0 None fixed
ffmpeg 3.21-community 4.3.2-r0 None fixed
ffmpeg 3.20-community 4.3.2-r0 None fixed
ffmpeg 3.19-community 4.3.2-r0 None fixed
ffmpeg 3.18-community 4.3.2-r0 None fixed
ffmpeg 3.17-community 4.3.2-r0 None fixed