MEDIUM · 5.5

CVE-2020-13904

FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_inpu...

Vulnerability Description

FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_input_format3 in libavformat/format.c.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
FfmpegFfmpeg2.8
CanonicalUbuntu Linux16.04
DebianDebian Linux9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-13904?

CVE-2020-13904 is a vulnerability with a CVSS score of 5.5 (MEDIUM). FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_inpu...

How severe is CVE-2020-13904?

CVE-2020-13904 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-13904?

Check the references section above for vendor advisories and patch information. Affected products include: Ffmpeg Ffmpeg, Canonical Ubuntu Linux, Debian Debian Linux.