Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-24995

Опубликовано: 30 мар. 2021
Источник: debian
EPSS Низкий

Описание

Buffer overflow vulnerability in sniff_channel_order function in aacdec_template.c in ffmpeg 3.1.2, allows attackers to execute arbitrary code (local).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegnot-affectedpackage

Примечания

  • https://trac.ffmpeg.org/ticket/8845

  • https://trac.ffmpeg.org/ticket/8859

  • https://trac.ffmpeg.org/ticket/8860

  • Support for 22.2 / channel_config 13 introduced in:

  • https://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=9c0beaf0d3bb72f6e83b3b155a598a9ec28c8468

  • Fixed by: https://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=d6f293353c94c7ce200f6e0975ae3de49787f91f

  • Introduced in https://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=9c0beaf0d3bb72f6e83b3b155a598a9ec28c8468

EPSS

Процентиль: 45%
0.00223
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 5 лет назад

Buffer overflow vulnerability in sniff_channel_order function in aacdec_template.c in ffmpeg 3.1.2, allows attackers to execute arbitrary code (local).

CVSS3: 7.8
nvd
почти 5 лет назад

Buffer overflow vulnerability in sniff_channel_order function in aacdec_template.c in ffmpeg 3.1.2, allows attackers to execute arbitrary code (local).

github
больше 3 лет назад

Buffer overflow vulnerability in sniff_channel_order function in aacdec_template.c in ffmpeg 3.1.2, allows attackers to execute arbitrary code (local).

EPSS

Процентиль: 45%
0.00223
Низкий