A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary code.
References
Link | Resource |
---|---|
https://trac.ffmpeg.org/ticket/8186 | Exploit Issue Tracking Patch Vendor Advisory |
https://www.debian.org/security/2021/dsa-4998 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-08-10T20:19:37
Updated: 2021-11-01T10:06:22
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-21688
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-08-10T21:15:07.723
Modified: 2021-11-30T18:54:08.730
Link: CVE-2020-21688
JSON object: View
Redhat Information
No data.
CWE