6.8
CVSSv2

CVE-2020-21688

Published: 10/08/2021 Updated: 30/11/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows malicious users to execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ffmpeg ffmpeg 4.2

debian debian linux 11.0

Vendor Advisories

Several security issues were fixed in FFmpeg ...
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed For the stable distribution (bullseye), these problems have been fixed in version 7:433-0+deb11u1 We recommend that you upgrade your ffmp ...