Bug 1186864 - (CVE-2020-22056) VUL-1: CVE-2020-22056: ffmpeg: A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the config_input function in af_acrossover.c.
(CVE-2020-22056)
VUL-1: CVE-2020-22056: ffmpeg: A Denial of Service vulnerability exists in FF...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P5 - None : Minor
: ---
Assigned To: E-mail List
Security Team bot
https://smash.suse.de/issue/301181/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-06-04 12:40 UTC by Gianluca Gabrielli
Modified: 2021-06-04 12:43 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gianluca Gabrielli 2021-06-04 12:40:47 UTC
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in
the config_input function in af_acrossover.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-22056
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-22056
https://trac.ffmpeg.org/ticket/8304
Comment 1 Gianluca Gabrielli 2021-06-04 12:43:08 UTC
The following packages don't implement the affected function `static av_cold void uninit(AVFilterContext *ctx)`:
 - SUSE:SLE-15-SP2:Update/ffmpeg   3.4.2
 - SUSE:SLE-15:Update/ffmpeg       3.4.2

The following package is already patched:
 - openSUSE:Factory/ffmpeg-4       4.4