Bug 1190725 - (CVE-2020-20897) VUL-0: CVE-2020-20897: ffmpeg: Buffer Overflow vulnerability in function filter_slice in libavfilter/vf_bm3d.c
(CVE-2020-20897)
VUL-0: CVE-2020-20897: ffmpeg: Buffer Overflow vulnerability in function filt...
Status: RESOLVED INVALID
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: E-mail List
Security Team bot
https://smash.suse.de/issue/310564/
CVSSv3.1:SUSE:CVE-2020-20897:6.5:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-09-21 14:01 UTC by Alexander Bergmann
Modified: 2021-09-22 13:48 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2021-09-21 14:01:42 UTC
CVE-2020-20897

Buffer Overflow vulnerability in function filter_slice in libavfilter/vf_bm3d.c
in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other
unspecified impacts.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-20897
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20897
https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/0749082eb93ea02fa4b770da86597450cec84054
https://trac.ffmpeg.org/ticket/8262
Comment 1 Alexander Bergmann 2021-09-22 13:48:16 UTC
The file libavfilter/vf_bm3d.c was introduced in version n4.3 and as far as I can tell there is no code equivalent else where.

Closed as invalid.