CVE-2020-20896 Information

Description

An issue was discovered in function latm_write_packet in libavformat/latmenc.c in Ffmpeg 4.2.1 allows attackers to cause a Denial of Service or other unspecified impacts due to a Null pointer dereference.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Reference

https://trac.ffmpeg.org/ticket/8273 https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/dd01947397b98e94c3f2a79d5820aaf4594f4d3b

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.8

Share on: