Bug 1186862 - (CVE-2020-22051) VUL-1: CVE-2020-22051: ffmpeg: A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the filter_frame function in vf_tile.c.
(CVE-2020-22051)
VUL-1: CVE-2020-22051: ffmpeg: A Denial of Service vulnerability exists in FF...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P5 - None : Minor
: ---
Assigned To: E-mail List
Security Team bot
https://smash.suse.de/issue/301156/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-06-04 12:26 UTC by Gianluca Gabrielli
Modified: 2021-06-04 12:28 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gianluca Gabrielli 2021-06-04 12:26:49 UTC
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in
the filter_frame function in vf_tile.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-22051
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-22051
http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=673fce6d40d9a594fb7a0ea17d296b7d3d9ea856
https://trac.ffmpeg.org/ticket/8313
Comment 1 Gianluca Gabrielli 2021-06-04 12:28:31 UTC
The following packages don't implement the affected function `static av_cold void uninit(AVFilterContext *ctx)`:
 - SUSE:SLE-15-SP2:Update/ffmpeg   3.4.2
 - SUSE:SLE-15:Update/ffmpeg       3.4.2

The following package is already patched:
 - openSUSE:Factory/ffmpeg-4       4.4