Vulnerability Description
decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ffmpeg | Ffmpeg | >= 4.3.1, < 4.4 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26532ExploitIssue TrackingThird Party Advisory
- https://github.com/FFmpeg/FFmpeg/commit/3e5959b3457f7f1856d997261e6ac672bba49e8bPatchThird Party Advisory
- https://github.com/FFmpeg/FFmpeg/commit/b0a8b40294ea212c1938348ff112ef1b9bf16bb3PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/01/msg00026.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202105-24Third Party Advisory
- https://www.debian.org/security/2021/dsa-4990Third Party Advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26532ExploitIssue TrackingThird Party Advisory
- https://github.com/FFmpeg/FFmpeg/commit/3e5959b3457f7f1856d997261e6ac672bba49e8bPatchThird Party Advisory
- https://github.com/FFmpeg/FFmpeg/commit/b0a8b40294ea212c1938348ff112ef1b9bf16bb3PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/01/msg00026.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202105-24Third Party Advisory
- https://www.debian.org/security/2021/dsa-4990Third Party Advisory
FAQ
What is CVE-2020-35965?
CVE-2020-35965 is a vulnerability with a CVSS score of 7.5 (HIGH). decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.
How severe is CVE-2020-35965?
CVE-2020-35965 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-35965?
Check the references section above for vendor advisories and patch information. Affected products include: Ffmpeg Ffmpeg, Debian Debian Linux.