Integer Overflow Vulnerability in Ffmpeg by Ffmpeg Developers
CVE-2021-38093

8.8HIGH

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
20 September 2021

What is CVE-2021-38093?

An integer overflow vulnerability exists in the 'filter_robert' function within the 'libavfilter/vf_convolution.c' file of Ffmpeg 4.2.1. This flaw may allow attackers to exploit the vulnerability, potentially resulting in a Denial of Service where users may be unable to use the software effectively. Attackers may manipulate inputs to trigger improper error handling or resource exhaustion, which can impact the stability and functionality of the application.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.