Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-79768
HistoryAug 11, 2021 - 12:00 a.m.

FFmpeg heap reuse after release vulnerability (CNVD-2021-79768)

2021-08-1100:00:00
China National Vulnerability Database
www.cnvd.org.cn
14

0.003 Low

EPSS

Percentile

65.8%

FFmpeg is a set of open source computer programs that can be used to record, convert, and stream digital audio and video under the LGPL or GPL license. av_freep function in libavutil/mem.c in FFmpeg version 4.2 is vulnerable to a heap-release post-reuse vulnerability. An attacker can exploit this vulnerability to execute arbitrary code.

CPENameOperatorVersion
ffmpeg ffmpegeq4.2