Integer Overflow Vulnerability in FFmpeg by Ffmpeg Project
CVE-2021-38090

8.8HIGH

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
20 September 2021

What is CVE-2021-38090?

An integer overflow vulnerability exists in the function filter16_roberts located in libavfilter/vf_convolution.c of FFmpeg 4.2.1. This flaw can be exploited by attackers to potentially disrupt service or induce other unspecified effects. Users of this software should review the specified versions to mitigate any associated risks.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.