CVE-2021-30123

Name
CVE-2021-30123
Description
FFmpeg <=4.3 contains a buffer overflow vulnerability in libavcodec through a crafted file that may lead to remote code execution.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=d6f293353c94c7ce200f6e0975ae3de49787f91f
Exploit https://trac.ffmpeg.org/ticket/8863
Exploit https://trac.ffmpeg.org/ticket/8845
Third Party Advisory https://security.gentoo.org/glsa/202105-24

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* ffmpeg >= None <= 4.3
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* ffmpeg >= None < 4.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ffmpeg 3.13-community 4.3.1-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable