CVE-2021-3566
Dashboard / Vulnerabilities / CVE-2021-3566
CVE-2021-3566
Published: 5 Aug 2021Last Modified: 17 Aug 2026
Summary:
Details: Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that references an image, followed by a file the triggers the tty demuxer, the contents of the second file will be copied into the output file verbatim (as long as the `-vcodec copy` option is passed to ffmpeg).
References: https://lists.debian.org/debian-lts-announce/2021/08/msg00018.html, https://github.com/FFmpeg/FFmpeg/commit/3bce9e9b3ea35c54bacccc793d7da99ea5157532#diff-74f6b92a0541378ad15de9c29c0a2b0c69881ad9ffc71abe568b88b535e00a7f
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
n4.2-dev
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
