UBUNTU-CVE-2021-3566
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3566
UBUNTU-CVE-2021-3566
Summary:
Details: Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that references an image, followed by a file the triggers the tty demuxer, the contents of the second file will be copied into the output file verbatim (as long as the `-vcodec copy` option is passed to ffmpeg).
References: https://ubuntu.com/security/CVE-2021-3566, https://github.com/FFmpeg/FFmpeg/commit/3bce9e9b3ea35c54bacccc793d7da99ea5157532#diff-74f6b92a0541378ad15de9c29c0a2b0c69881ad9ffc71abe568b88b535e00a7f, https://ubuntu.com/security/notices/USN-5167-1, https://www.cve.org/CVERecord?id=CVE-2021-3566
Affected packages
Package
Name: ffmpeg
Purl: pkg:deb/ubuntu/ffmpeg@7:2.8.17-0ubuntu0.1+esm4?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
