CVE-2020-35965 log
| Source |
|
| Severity | Medium |
| Remote | No |
| Type | Arbitrary code execution |
| Description | decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-1397 | ffmpeg | 2:4.3.2-6 | 2:4.4-1 | Medium | Fixed |
| Notes |
|---|
Only one of the two commits referenced in the CVE advisory appears to have been backported to FFmpeg version 4.3.2. |