File _patchinfo of Package patchinfo.19994
<patchinfo incident="19994">
<issue tracker="cve" id="2020-22023"/>
<issue tracker="cve" id="2020-21041"/>
<issue tracker="cve" id="2020-22019"/>
<issue tracker="cve" id="2020-22034"/>
<issue tracker="cve" id="2020-22025"/>
<issue tracker="cve" id="2020-22049"/>
<issue tracker="cve" id="2020-22043"/>
<issue tracker="cve" id="2020-22017"/>
<issue tracker="cve" id="2019-9721"/>
<issue tracker="cve" id="2020-13904"/>
<issue tracker="cve" id="2020-22020"/>
<issue tracker="cve" id="2020-22016"/>
<issue tracker="cve" id="2020-22021"/>
<issue tracker="cve" id="2020-20448"/>
<issue tracker="cve" id="2020-22038"/>
<issue tracker="cve" id="2019-17539"/>
<issue tracker="cve" id="2020-20451"/>
<issue tracker="cve" id="2020-22031"/>
<issue tracker="cve" id="2020-22033"/>
<issue tracker="cve" id="2020-22026"/>
<issue tracker="cve" id="2020-22044"/>
<issue tracker="cve" id="2020-22048"/>
<issue tracker="cve" id="2020-22015"/>
<issue tracker="cve" id="2020-22022"/>
<issue tracker="cve" id="2020-22032"/>
<issue tracker="cve" id="2020-22039"/>
<issue tracker="cve" id="2020-22054"/>
<issue tracker="cve" id="2020-22046"/>
<issue tracker="cve" id="2020-21688"/>
<issue tracker="cve" id="2020-21697"/>
<issue tracker="cve" id="2021-38114"/>
<issue tracker="bnc" id="1189348"></issue>
<issue tracker="bnc" id="1189350"></issue>
<issue tracker="bnc" id="1189142"></issue>
<issue tracker="bnc" id="1186406">VUL-0: CVE-2020-21041: ffmpeg: Buffer Overflow vulnerability via apng_do_inverse_blend in libavcodec/pngenc.c</issue>
<issue tracker="bnc" id="1186762">VUL-1: CVE-2020-22043: ffmpeg: Denial of Service vulnerability exists due to a memory leak at the fifo_alloc_common function in libavutil/fifo.c</issue>
<issue tracker="bnc" id="1186658">VUL-1: CVE-2020-20451: ffmpeg: Denial of Service issue due to resource management errors via fftools/cmdutils.c</issue>
<issue tracker="bnc" id="1186758">VUL-1: CVE-2020-22039: ffmpeg: Denial of Service vulnerability exists due to a memory leak in the inavi_add_ientry function</issue>
<issue tracker="bnc" id="1186660">VUL-1: CVE-2020-20448: ffmpeg: Divide By Zero issue via libavcodec/ratecontrol.c</issue>
<issue tracker="bnc" id="1172640">VUL-0: CVE-2020-13904: ffmpeg: use-after-free via a crafted EXTINF duration in an m3u8 file</issue>
<issue tracker="bnc" id="1186604">VUL-1: CVE-2020-22023: ffmpeg: A heap-based Buffer Overflow vulnerability exists in filter_frame at libavfilter/vf_bitplanenoise.c</issue>
<issue tracker="bnc" id="1186614">VUL-1: CVE-2020-22032: ffmpeg: A heap-based Buffer Overflow vulnerability exists at libavfilter/vf_edgedetect.c in gaussian_blur()</issue>
<issue tracker="bnc" id="1186597">VUL-1: CVE-2020-22019: ffmpeg: Buffer Overflow vulnerability in convolution_y_10bit() in libavfilter/vf_vmafmotion.c</issue>
<issue tracker="bnc" id="1186861">VUL-0: CVE-2020-22049: ffmpeg: A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c.</issue>
<issue tracker="bnc" id="1186586">VUL-1: CVE-2020-22021: ffmpeg: Buffer Overflow vulnerability in filter_edges function in libavfilter/vf_yadif.c</issue>
<issue tracker="bnc" id="1186598">VUL-1: CVE-2020-22016: ffmpeg: A heap-based Buffer Overflow vulnerability at libavcodec/get_bits.h when writing .mov files</issue>
<issue tracker="bnc" id="1186596">VUL-1: CVE-2020-22015: ffmpeg: Buffer Overflow vulnerability in mov_write_video_tag() due to the out of bounds in libavformat/movenc.c</issue>
<issue tracker="bnc" id="1186863">VUL-0: CVE-2020-22054: ffmpeg: A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c.</issue>
<issue tracker="bnc" id="1186605">VUL-1: CVE-2020-22025: ffmpeg: A heap-based Buffer Overflow vulnerability exists in gaussian_blur at libavfilter/vf_edgedetect.c,</issue>
<issue tracker="bnc" id="1186587">VUL-1: CVE-2020-22020: ffmpeg: Buffer Overflow vulnerability in build_diff_map() in libavfilter/vf_fieldmatch.c</issue>
<issue tracker="bnc" id="1186763">VUL-1: CVE-2020-22044: ffmpeg: Denial of Service vulnerability exists due to a memory leak in the url_open_dyn_buf_internal function in libavformat/aviobuf.c</issue>
<issue tracker="bnc" id="1186757">VUL-1: CVE-2020-22038: ffmpeg: Denial of Service vulnerability exists due to a memory leak in the ff_v4l2_m2m_create_context function in v4l2_m2m.c</issue>
<issue tracker="bnc" id="1129714">VUL-1: CVE-2019-9721: ffmpeg: denial of service in the subtitle decoder in handle_open_brace from libavcodec/htmlsubtitles.c</issue>
<issue tracker="bnc" id="1186600">VUL-1: CVE-2020-22017: ffmpeg: A heap-based Buffer Overflow vulnerability exists in ff_fill_rectangle() in libavfilter/drawutils.c</issue>
<issue tracker="bnc" id="1186583">VUL-1: CVE-2020-22026: ffmpeg: Buffer Overflow vulnerability exists in config_input() at libavfilter/af_tremolo.c</issue>
<issue tracker="bnc" id="1186603">VUL-1: CVE-2020-22022: ffmpeg: A heap-based Buffer Overflow vulnerability exists in filter_frame at libavfilter/vf_fieldorder.c</issue>
<issue tracker="bnc" id="1186615">VUL-1: CVE-2020-22033: ffmpeg: A heap-based Buffer Overflow Vulnerability exists at libavfilter/vf_vmafmotion.c in convolution_y_8bit()</issue>
<issue tracker="bnc" id="1186616">VUL-1: CVE-2020-22034: ffmpeg: A heap-based Buffer Overflow vulnerability exists at libavfilter/vf_floodfill.c</issue>
<issue tracker="bnc" id="1186859">VUL-0: CVE-2020-22048: ffmpeg: A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c.</issue>
<issue tracker="bnc" id="1186849">VUL-0: CVE-2020-22046: ffmpeg: A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c.</issue>
<issue tracker="bnc" id="1186613">VUL-1: CVE-2020-22031: ffmpeg: A Heap-based Buffer Overflow vulnerability exists at libavfilter/vf_w3fdif.c in filter16_complex_low()</issue>
<packager>AZhou</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for ffmpeg</summary>
<description>This update for ffmpeg fixes the following issues:
- CVE-2019-9721: Fixed a denial of service in the subtitle decoder in handle_open_brace from libavcodec/htmlsubtitles.c (bsc#1129714).
- CVE-2020-22046: Fixed a denial of service vulnerability due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c (bsc#1186849).
- CVE-2020-22048: Fixed a denial of service vulnerability due to a memory leak in the ff_frame_pool_get function in framepool.c (bsc#1186859).
- CVE-2020-22049: Fixed a denial of service vulnerability caused by a memory leak in the wtvfile_open_sector function in wtvdec.c (bsc#1186861).
- CVE-2020-22054: Fixed a denial of service vulnerability due to a memory leak in the av_dict_set function in dict.c (bsc#1186863).
- CVE-2020-13904: Fixed use-after-free via a crafted EXTINF duration in an m3u8 file (bsc#1172640).
- CVE-2020-21041: Fixed buffer overflow vulnerability via apng_do_inverse_blend in libavcodec/pngenc.c (bsc#1186406).
- CVE-2019-17539: Fixed NULL pointer dereference in avcodec_open2 in libavcodec/utils.c (bsc# 1154065).
- CVE-2020-22026: Fixed buffer overflow vulnerability in config_input() at libavfilter/af_tremolo.c (bsc#1186583).
- CVE-2020-22021: Fixed buffer overflow vulnerability in filter_edges function in libavfilter/vf_yadif.c (bsc#1186586).
- CVE-2020-22020: Fixed buffer overflow vulnerability in build_diff_map() in libavfilter/vf_fieldmatch.c (bsc#1186587).
- CVE-2020-22015: Fixed buffer overflow vulnerability in mov_write_video_tag() due to the out of bounds in libavformat/movenc.c (bsc#1186596).
- CVE-2020-22016: Fixed a heap-based Buffer Overflow vulnerability at libavcodec/get_bits.h when writing .mov files (bsc#1186598).
- CVE-2020-22017: Fixed a heap-based Buffer Overflow vulnerability in ff_fill_rectangle() in libavfilter/drawutils.c (bsc#1186600).
- CVE-2020-22022: Fixed a heap-based Buffer Overflow vulnerability in filter_frame at libavfilter/vf_fieldorder.c (bsc#1186603).
- CVE-2020-22023: Fixed a heap-based Buffer Overflow vulnerability in filter_frame at libavfilter/vf_bitplanenoise.c (bsc#1186604)
- CVE-2020-22025: Fixed a heap-based Buffer Overflow vulnerability in gaussian_blur at libavfilter/vf_edgedetect.c (bsc#1186605).
- CVE-2020-22031: Fixed a heap-based Buffer Overflow vulnerability at libavfilter/vf_w3fdif.c in filter16_complex_low() (bsc#1186613).
- CVE-2020-22032: Fixed a heap-based Buffer Overflow vulnerability at libavfilter/vf_edgedetect.c in gaussian_blur() (bsc#1186614).
- CVE-2020-22034: Fixed a heap-based Buffer Overflow vulnerability at libavfilter/vf_floodfill.c (bsc#1186616).
- CVE-2020-20451: Fixed denial of service issue due to resource management errors via fftools/cmdutils.c (bsc#1186658).
- CVE-2020-20448: Fixed divide by zero issue via libavcodec/ratecontrol.c (bsc#1186660).
- CVE-2020-22038: Fixed denial of service vulnerability due to a memory leak in the ff_v4l2_m2m_create_context function in v4l2_m2m.c (bsc#1186757).
- CVE-2020-22039: Fixed denial of service vulnerability due to a memory leak in the inavi_add_ientry function (bsc#1186758).
- CVE-2020-22043: Fixed denial of service vulnerability due to a memory leak at the fifo_alloc_common function in libavutil/fifo.c (bsc#1186762).
- CVE-2020-22044: Fixed denial of service vulnerability due to a memory leak in the url_open_dyn_buf_internal function in libavformat/aviobuf.c (bsc#1186763).
- CVE-2020-22033,CVE-2020-22019: Fixed a heap-based Buffer Overflow Vulnerability at libavfilter/vf_vmafmotion.c in convolution_y_8bit() and in convolution_y_10bit() in libavfilter/vf_vmafmotion.c (bsc#1186615, bsc#1186597).
- CVE-2020-21688: Fixed a heap-use-after-free in the av_freep function in libavutil/mem.c (bsc#1189348).
- CVE-2020-21697: Fixed a heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpegenc.c (bsc#1189350).
- CVE-2021-38114: Fixed a not checked return value of the init_vlc function (bsc#1189142).
</description>
</patchinfo>