CVE-2021-3566 Affecting libavutil-devel package, versions <3.4.2-11.17.1
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-SLES153-LIBAVUTILDEVEL-2662513
- published 14 Apr 2022
- disclosed 26 Oct 2021
Introduced: 26 Oct 2021
CVE-2021-3566 Open this link in a new tabHow to fix?
Upgrade SLES:15.3
libavutil-devel
to version 3.4.2-11.17.1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream libavutil-devel
package and not the libavutil-devel
package as distributed by SLES
.
See How to fix?
for SLES:15.3
relevant fixed versions and status.
Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that references an image, followed by a file the triggers the tty demuxer, the contents of the second file will be copied into the output file verbatim (as long as the -vcodec copy
option is passed to ffmpeg).
References
- https://www.suse.com/security/cve/CVE-2021-3566.html
- https://lists.suse.com/pipermail/sle-security-updates/2021-October/009650.html
- https://www.suse.com/support/update/announcement/2021/suse-su-20213521-1/
- https://bugzilla.suse.com/1186756
- https://bugzilla.suse.com/1187852
- https://bugzilla.suse.com/1189166
- https://bugzilla.suse.com/1190718
- https://bugzilla.suse.com/1190719
- https://bugzilla.suse.com/1190722
- https://bugzilla.suse.com/1190723
- https://bugzilla.suse.com/1190726
- https://bugzilla.suse.com/1190729
- https://bugzilla.suse.com/1190733
- https://bugzilla.suse.com/1190734
- https://bugzilla.suse.com/1190735
- https://www.suse.com/security/cve/CVE-2020-20891/
- https://www.suse.com/security/cve/CVE-2020-20892/
- https://www.suse.com/security/cve/CVE-2020-20895/
- https://www.suse.com/security/cve/CVE-2020-20896/
- https://www.suse.com/security/cve/CVE-2020-20899/
- https://www.suse.com/security/cve/CVE-2020-20902/
- https://www.suse.com/security/cve/CVE-2020-22037/
- https://www.suse.com/security/cve/CVE-2020-35965/
- https://www.suse.com/security/cve/CVE-2021-3566/
- https://www.suse.com/security/cve/CVE-2021-38092/
- https://www.suse.com/security/cve/CVE-2021-38093/
- https://www.suse.com/security/cve/CVE-2021-38094/
- https://www.suse.com/support/security/rating/
- https://github.com/FFmpeg/FFmpeg/commit/3bce9e9b3ea35c54bacccc793d7da99ea5157532#diff-74f6b92a0541378ad15de9c29c0a2b0c69881ad9ffc71abe568b88b535e00a7f
- https://lists.debian.org/debian-lts-announce/2021/08/msg00018.html