Vulnerability CVE-2021-38092: Information

Description

Integer Overflow vulnerability in function filter_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: Sept. 20, 2021
Modified: Sept. 23, 2021
Error type identifier: CWE-190

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
ffmpegsisyphus4.2.2-alt16.1.1-alt3ALT-PU-2020-1014-1243947Fixed
ffmpegp104.2.2-alt14.4.4-alt1ALT-PU-2020-1014-1243947Fixed
ffmpegp94.2.3-alt14.3.6-alt1ALT-PU-2020-2032-1252247Fixed
ffmpegc10f14.2.2-alt14.4.4-alt1ALT-PU-2020-1014-1243947Fixed
ffmpegc9f24.2.3-alt14.3.6-alt1ALT-PU-2020-2032-1252247Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/99f8d32129dd233d4eb2efa44678a0bc44869f23
  • Mailing List
  • Patch
  • Vendor Advisory
https://trac.ffmpeg.org/ticket/8263
  • Exploit
  • Issue Tracking
  • Vendor Advisory
    1. Configuration 1

      cpe:2.3:a:ffmpeg:ffmpeg:4.2.1:*:*:*:*:*:*:*