CVE-2020-35965 - log back

CVE-2020-35965 edited at 17 Mar 2021 12:11:47
References
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26532
https://github.com/FFmpeg/FFmpeg/commit/3e5959b3457f7f1856d997261e6ac672bba49e8b
https://github.com/FFmpeg/FFmpeg/commit/b0a8b40294ea212c1938348ff112ef1b9bf16bb3
+ https://trac.ffmpeg.org/ticket/9155
https://github.com/FFmpeg/FFmpeg/commit/a53ffb15d8ae9bed14041b4cf62e436852e95431
CVE-2020-35965 edited at 05 Mar 2021 10:14:48
Notes
+ Only one of the two commits referenced in the CVE advisory appears to have been backported to FFmpeg version 4.3.2.
CVE-2020-35965 edited at 05 Mar 2021 10:11:33
References
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26532
https://github.com/FFmpeg/FFmpeg/commit/3e5959b3457f7f1856d997261e6ac672bba49e8b
https://github.com/FFmpeg/FFmpeg/commit/b0a8b40294ea212c1938348ff112ef1b9bf16bb3
+ https://github.com/FFmpeg/FFmpeg/commit/a53ffb15d8ae9bed14041b4cf62e436852e95431
CVE-2020-35965 edited at 04 Jan 2021 10:33:33
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary code execution
Description
+ decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.
References
+ https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26532
+ https://github.com/FFmpeg/FFmpeg/commit/3e5959b3457f7f1856d997261e6ac672bba49e8b
+ https://github.com/FFmpeg/FFmpeg/commit/b0a8b40294ea212c1938348ff112ef1b9bf16bb3
Notes
CVE-2020-35965 created at 04 Jan 2021 10:31:02