Integer overflow in FFmpeg - CVE-2021-28429

 

Integer overflow in FFmpeg - CVE-2021-28429

Published: December 5, 2023


Vulnerability identifier: #VU83856
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28429
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to integer overflow within the av_timecode_make_string in libavutil/timecode.c. A local user can pass specially crafted data to the application, trigger integer overflow and cause a denial of service condition on the target system.


Affected software

FFmpeg
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
Desktop Applications Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
libavdevice-ffmpeg56 (Ubuntu package)
libavformat57 (Ubuntu package)
libavresample3 (Ubuntu package)
libavutil55 (Ubuntu package)
libpostproc54 (Ubuntu package)
libswresample2 (Ubuntu package)
libswscale4 (Ubuntu package)
libav-tools (Ubuntu package)
libavcodec-ffmpeg-extra56 (Ubuntu package)
libavcodec-ffmpeg56 (Ubuntu package)
libavcodec-extra (Ubuntu package)
libavfilter-ffmpeg5 (Ubuntu package)
libavformat-ffmpeg56 (Ubuntu package)
libavresample-ffmpeg2 (Ubuntu package)
libavutil-ffmpeg54 (Ubuntu package)
libpostproc-ffmpeg53 (Ubuntu package)
libswresample-ffmpeg1 (Ubuntu package)
libswscale-ffmpeg3 (Ubuntu package)
ffmpeg (Ubuntu package)
libavfilter-extra6 (Ubuntu package)
libavfilter6 (Ubuntu package)
libavcodec-extra58 (Ubuntu package)
libavcodec58 (Ubuntu package)
libavdevice58 (Ubuntu package)
libavfilter-extra (Ubuntu package)
libavfilter-extra7 (Ubuntu package)
libavfilter7 (Ubuntu package)
libavformat58 (Ubuntu package)
libavutil56 (Ubuntu package)
libavresample4 (Ubuntu package)
libavdevice57 (Ubuntu package)
libavcodec57 (Ubuntu package)
libavcodec-extra57 (Ubuntu package)
libswresample3 (Ubuntu package)
libpostproc55 (Ubuntu package)
libswscale5 (Ubuntu package)
libavresample-devel
libavformat-devel
ffmpeg-debugsource
libavdevice-devel
ffmpeg-debuginfo
libpostproc54-debuginfo
libavdevice57
libswresample-devel
ffmpeg-private-devel
libavfilter6-debuginfo
libswresample2
libpostproc54
libavresample3-debuginfo
libswscale-devel
libswresample2-debuginfo
libavcodec57
libavcodec57-debuginfo
libavfilter6
libavdevice57-32bit-debuginfo
libswscale4-32bit
libavfilter6-32bit
libavutil55-32bit-debuginfo
libpostproc54-32bit
libavformat57-32bit
libswresample2-32bit
libavresample3-32bit-debuginfo
libavcodec57-32bit
libavfilter6-32bit-debuginfo
libswscale4
libavformat57-32bit-debuginfo
libswresample2-32bit-debuginfo
libavutil55-32bit
libavdevice57-32bit
libpostproc54-32bit-debuginfo
libavresample3-32bit
libswscale4-32bit-debuginfo
libavcodec57-32bit-debuginfo
libavcodec-devel
ffmpeg
libavdevice57-debuginfo
libavformat57
libavfilter-devel
libavformat57-debuginfo
libswscale4-debuginfo
libpostproc-devel
libavutil-devel
libavutil55-debuginfo
libavresample3
libavutil55
libavdevice
ffmpeg-devel
ffmpeg-libs
Isolation Segment
VMware Tanzu Application Service for VMs

How to mitigate CVE-2021-28429

Install updates from vendor's website.

FFmpeg - update to 4.2.1
libavdevice-ffmpeg56 (Ubuntu package) - update to Ubuntu Pro
libavformat57 (Ubuntu package) - update to Ubuntu Pro
libavresample3 (Ubuntu package) - update to Ubuntu Pro
libavutil55 (Ubuntu package) - update to Ubuntu Pro
libpostproc54 (Ubuntu package) - update to Ubuntu Pro
libswresample2 (Ubuntu package) - update to Ubuntu Pro
libswscale4 (Ubuntu package) - update to Ubuntu Pro
libav-tools (Ubuntu package) - update to Ubuntu Pro
libavcodec-ffmpeg-extra56 (Ubuntu package) - update to Ubuntu Pro
libavcodec-ffmpeg56 (Ubuntu package) - update to Ubuntu Pro
libavcodec-extra (Ubuntu package) - update to Ubuntu Pro
libavfilter-ffmpeg5 (Ubuntu package) - update to Ubuntu Pro
libavformat-ffmpeg56 (Ubuntu package) - update to Ubuntu Pro
libavresample-ffmpeg2 (Ubuntu package) - update to Ubuntu Pro
libavutil-ffmpeg54 (Ubuntu package) - update to Ubuntu Pro
libpostproc-ffmpeg53 (Ubuntu package) - update to Ubuntu Pro
libswresample-ffmpeg1 (Ubuntu package) - update to Ubuntu Pro
libswscale-ffmpeg3 (Ubuntu package) - update to Ubuntu Pro
ffmpeg (Ubuntu package) - update to Ubuntu Pro
libavfilter-extra6 (Ubuntu package) - update to Ubuntu Pro
libavfilter6 (Ubuntu package) - update to Ubuntu Pro
libavcodec-extra58 (Ubuntu package) - update to Ubuntu Pro
libavcodec58 (Ubuntu package) - update to Ubuntu Pro
libavdevice58 (Ubuntu package) - update to Ubuntu Pro
libavfilter-extra (Ubuntu package) - update to Ubuntu Pro
libavfilter-extra7 (Ubuntu package) - update to Ubuntu Pro
libavfilter7 (Ubuntu package) - update to Ubuntu Pro
libavformat58 (Ubuntu package) - update to Ubuntu Pro
libavutil56 (Ubuntu package) - update to Ubuntu Pro
libavresample4 (Ubuntu package) - update to Ubuntu Pro
libavdevice57 (Ubuntu package) - update to Ubuntu Pro
libavcodec57 (Ubuntu package) - update to Ubuntu Pro
libavcodec-extra57 (Ubuntu package) - update to Ubuntu Pro
libswresample3 (Ubuntu package) - update to Ubuntu Pro
libpostproc55 (Ubuntu package) - update to Ubuntu Pro
libswscale5 (Ubuntu package) - update to Ubuntu Pro
Isolation Segment - addressed in versions 2.11.42, 2.13.27, 3.0.20, 4.0.12
VMware Tanzu Application Service for VMs - addressed in versions 2.11.48, 2.13.30, 3.0.20, 4.0.12
libavresample-devel - update to 3.4.2-150200.11.31.1
libavformat-devel - update to 3.4.2-150200.11.31.1
ffmpeg-debugsource - update to 3.4.2-150200.11.31.1
libavdevice-devel - update to 3.4.2-150200.11.31.1
ffmpeg-debuginfo - update to 3.4.2-150200.11.31.1
libpostproc54-debuginfo - update to 3.4.2-150200.11.31.1
libavdevice57 - update to 3.4.2-150200.11.31.1
libswresample-devel - update to 3.4.2-150200.11.31.1
ffmpeg-private-devel - update to 3.4.2-150200.11.31.1
libavfilter6-debuginfo - update to 3.4.2-150200.11.31.1
libswresample2 - update to 3.4.2-150200.11.31.1
libpostproc54 - update to 3.4.2-150200.11.31.1
libavresample3-debuginfo - update to 3.4.2-150200.11.31.1
libswscale-devel - update to 3.4.2-150200.11.31.1
libswresample2-debuginfo - update to 3.4.2-150200.11.31.1
libavcodec57 - update to 3.4.2-150200.11.31.1
libavcodec57-debuginfo - update to 3.4.2-150200.11.31.1
libavfilter6 - update to 3.4.2-150200.11.31.1
libavdevice57-32bit-debuginfo - update to 3.4.2-150200.11.31.1
libswscale4-32bit - update to 3.4.2-150200.11.31.1
libavfilter6-32bit - update to 3.4.2-150200.11.31.1
libavutil55-32bit-debuginfo - update to 3.4.2-150200.11.31.1
libpostproc54-32bit - update to 3.4.2-150200.11.31.1
libavformat57-32bit - update to 3.4.2-150200.11.31.1
libswresample2-32bit - update to 3.4.2-150200.11.31.1
libavresample3-32bit-debuginfo - update to 3.4.2-150200.11.31.1
libavcodec57-32bit - update to 3.4.2-150200.11.31.1
libavfilter6-32bit-debuginfo - update to 3.4.2-150200.11.31.1
libswscale4 - update to 3.4.2-150200.11.31.1
libavformat57-32bit-debuginfo - update to 3.4.2-150200.11.31.1
libswresample2-32bit-debuginfo - update to 3.4.2-150200.11.31.1
libavutil55-32bit - update to 3.4.2-150200.11.31.1
libavdevice57-32bit - update to 3.4.2-150200.11.31.1
libpostproc54-32bit-debuginfo - update to 3.4.2-150200.11.31.1
libavresample3-32bit - update to 3.4.2-150200.11.31.1
libswscale4-32bit-debuginfo - update to 3.4.2-150200.11.31.1
libavcodec57-32bit-debuginfo - update to 3.4.2-150200.11.31.1
libavcodec-devel - update to 3.4.2-150200.11.31.1
ffmpeg - update to 3.4.2-150200.11.31.1
libavdevice57-debuginfo - update to 3.4.2-150200.11.31.1
libavformat57 - update to 3.4.2-150200.11.31.1
libavfilter-devel - update to 3.4.2-150200.11.31.1
libavformat57-debuginfo - update to 3.4.2-150200.11.31.1
libswscale4-debuginfo - update to 3.4.2-150200.11.31.1
libpostproc-devel - update to 3.4.2-150200.11.31.1
libavutil-devel - update to 3.4.2-150200.11.31.1
libavutil55-debuginfo - update to 3.4.2-150200.11.31.1
libavresample3 - update to 3.4.2-150200.11.31.1
libavutil55 - update to 3.4.2-150200.11.31.1
libavdevice - addressed in versions 4.2.4-14, 4.2.4-15
ffmpeg-debuginfo - addressed in versions 4.2.4-14, 4.2.4-15
ffmpeg-debugsource - addressed in versions 4.2.4-14, 4.2.4-15
ffmpeg-devel - addressed in versions 4.2.4-14, 4.2.4-15
ffmpeg-libs - addressed in versions 4.2.4-14, 4.2.4-15
ffmpeg - addressed in versions 4.2.4-14, 4.2.4-15

External References

Related Security Bulletins