Improper validation of array index in FFmpeg - CVE-2021-33815

 

Improper validation of array index in FFmpeg - CVE-2021-33815

Published: December 27, 2023


Vulnerability identifier: #VU84800
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33815
CWE-ID: CWE-129
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to an out-of-bounds array access within the dwa_uncompress() function in libavcodec/exr.c. A remote attacker can trick the victim to open a specially crafted image, trigger memory corruption and execute arbitrary code on the system.


Affected software

FFmpeg
Gentoo Linux
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client

How to mitigate CVE-2021-33815

Install updates from vendor's website.

FFmpeg - update to 5.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405

External References

Related Security Bulletins