Candidate: CVE-2020-35965 PublicDate: 2021-01-04 02:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35965 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26532 https://github.com/FFmpeg/FFmpeg/commit/3e5959b3457f7f1856d997261e6ac672bba49e8b https://github.com/FFmpeg/FFmpeg/commit/b0a8b40294ea212c1938348ff112ef1b9bf16bb3 Description: decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_ffmpeg: upstream: https://github.com/FFmpeg/FFmpeg/commit/3e5959b3457f7f1856d997261e6ac672bba49e8b upstream: https://github.com/FFmpeg/FFmpeg/commit/b0a8b40294ea212c1938348ff112ef1b9bf16bb3 upstream_ffmpeg: released (4.4) precise/esm_ffmpeg: DNE trusty_ffmpeg: ignored (out of standard support) trusty/esm_ffmpeg: DNE xenial_ffmpeg: ignored (end of standard support, was needed) bionic_ffmpeg: needed focal_ffmpeg: needed groovy_ffmpeg: ignored (reached end-of-life) hirsute_ffmpeg: released (7:4.3.2-0+deb11u1ubuntu1) impish_ffmpeg: not-affected (7:4.4-6ubuntu5) jammy_ffmpeg: not-affected (7:4.4.1-3ubuntu2) devel_ffmpeg: not-affected (7:4.4.1-3ubuntu2)