CVE-2021-30123

FFmpeg <=4.3 contains a buffer overflow vulnerability in libavcodec through a crafted file that may lead to remote code execution.

Summary:

FFmpeg <=4.3 contains a buffer overflow vulnerability in libavcodec through a crafted file that may lead to remote code execution.

Reference Links(if available):

  • http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=d6f293353c94c7ce200f6e0975ae3de49787f91f
  • https://trac.ffmpeg.org/ticket/8863
  • https://trac.ffmpeg.org/ticket/8845
  • https://security.gentoo.org/glsa/202105-24
  • CVSS Score (if available)

    v2: / LOWAV:N/AC:M/Au:N/C:P/I:P/A:P

    v3: / HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

    Links to Exploits(if available)