VYPR
Critical severity9.8NVD Advisory· Published Apr 28, 2020· Updated Jun 17, 2026

CVE-2020-12284

CVE-2020-12284

Description

cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • FFmpeg/Ffmpeg3 versions
    cpe:2.3:a:ffmpeg:ffmpeg:4.1:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:ffmpeg:ffmpeg:4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:4.2.2:*:*:*:*:*:*:*
    • (no CPE)range: 4.1, 4.2.2
  • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*+ 2 more
    • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • FFmpeg/libavcodec/cbs_jpeg.cdescription

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.