Out-of-bounds Read Affecting libavutil-devel package, versions <3.4.2-11.17.1
Threat Intelligence
EPSS
0.23% (62nd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-SLES153-LIBAVUTILDEVEL-2660893
- published 14 Apr 2022
- disclosed 26 Oct 2021
Introduced: 26 Oct 2021
CVE-2020-20902 Open this link in a new tabHow to fix?
Upgrade SLES:15.3
libavutil-devel
to version 3.4.2-11.17.1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream libavutil-devel
package and not the libavutil-devel
package as distributed by SLES
.
See How to fix?
for SLES:15.3
relevant fixed versions and status.
A CWE-125: Out-of-bounds read vulnerability exists in long_term_filter function in g729postfilter.c in FFmpeg 4.2.1 during computation of the denominator of pseudo-normalized correlation R'(0), that could result in disclosure of information.
References
- https://www.suse.com/security/cve/CVE-2020-20902.html
- https://lists.suse.com/pipermail/sle-security-updates/2021-October/009650.html
- https://www.suse.com/support/update/announcement/2021/suse-su-20213521-1/
- https://bugzilla.suse.com/1186756
- https://bugzilla.suse.com/1187852
- https://bugzilla.suse.com/1189166
- https://bugzilla.suse.com/1190718
- https://bugzilla.suse.com/1190719
- https://bugzilla.suse.com/1190722
- https://bugzilla.suse.com/1190723
- https://bugzilla.suse.com/1190726
- https://bugzilla.suse.com/1190729
- https://bugzilla.suse.com/1190733
- https://bugzilla.suse.com/1190734
- https://bugzilla.suse.com/1190735
- https://www.suse.com/security/cve/CVE-2020-20891/
- https://www.suse.com/security/cve/CVE-2020-20892/
- https://www.suse.com/security/cve/CVE-2020-20895/
- https://www.suse.com/security/cve/CVE-2020-20896/
- https://www.suse.com/security/cve/CVE-2020-20899/
- https://www.suse.com/security/cve/CVE-2020-20902/
- https://www.suse.com/security/cve/CVE-2020-22037/
- https://www.suse.com/security/cve/CVE-2020-35965/
- https://www.suse.com/security/cve/CVE-2021-3566/
- https://www.suse.com/security/cve/CVE-2021-38092/
- https://www.suse.com/security/cve/CVE-2021-38093/
- https://www.suse.com/security/cve/CVE-2021-38094/
- https://www.suse.com/support/security/rating/
- http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=0c61661a2cbe1b8b284c80ada1c2fdddf4992cad
- https://trac.ffmpeg.org/ticket/8176
- http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=0c61661a2cbe1b8b284c80ada1c2fdddf4992cad
CVSS Scores
version 3.1