CVE-2020-13904

NameCVE-2020-13904
DescriptionFFmpeg 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_input_format3 in libavformat/format.c.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-2291-1, DSA-4722-1
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ffmpeg (PTS)stretch7:3.2.14-1~deb9u1vulnerable
stretch (security)7:3.2.15-0+deb9u1fixed
buster, buster (security)7:4.1.6-1~deb10u1fixed
bullseye, sid7:4.3.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ffmpegsourcestretch7:3.2.15-0+deb9u1DLA-2291-1
ffmpegsourcebuster7:4.1.6-1~deb10u1DSA-4722-1
ffmpegsource(unstable)7:4.3.1-1

Notes

https://patchwork.ffmpeg.org/project/ffmpeg/patch/20200529033905.41926-1-lq@chinaffmpeg.org/
https://github.com/FFmpeg/FFmpeg/commit/9dfb19baeb86a8bb02c53a441682c6e9a6e104cc
https://trac.ffmpeg.org/ticket/8673

Search for package or bug name: Reporting problems