Unrated severityNVD Advisory· Published Aug 5, 2021· Updated Aug 3, 2024
CVE-2021-3566
CVE-2021-3566
Description
Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that references an image, followed by a file the triggers the tty demuxer, the contents of the second file will be copied into the output file verbatim (as long as the -vcodec copy option is passed to ffmpeg).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19- ffmpeg/ffmpegdescription
- osv-coords17 versionspkg:rpm/opensuse/ffmpeg&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/ffmpeg&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2pkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3pkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP2pkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2pkg:rpm/suse/ffmpeg&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3
< 3.4.2-11.17.1+ 16 more
- (no CPE)range: < 3.4.2-11.17.1
- (no CPE)range: < 3.4.2-150000.4.44.1
- (no CPE)range: < 3.4.2-150000.4.44.1
- (no CPE)range: < 3.4.2-150000.4.44.1
- (no CPE)range: < 3.4.2-150000.4.44.1
- (no CPE)range: < 3.4.2-150000.4.44.1
- (no CPE)range: < 3.4.2-11.17.1
- (no CPE)range: < 3.4.2-11.17.1
- (no CPE)range: < 3.4.2-11.17.1
- (no CPE)range: < 3.4.2-11.17.1
- (no CPE)range: < 3.4.2-150000.4.44.1
- (no CPE)range: < 3.4.2-150000.4.44.1
- (no CPE)range: < 3.4.2-150000.4.44.1
- (no CPE)range: < 3.4.2-150000.4.44.1
- (no CPE)range: < 3.4.2-150000.4.44.1
- (no CPE)range: < 3.4.2-11.17.1
- (no CPE)range: < 3.4.2-11.17.1
Patches
Vulnerability mechanics
References
2- github.com/FFmpeg/FFmpeg/commit/3bce9e9b3ea35c54bacccc793d7da99ea5157532mitrex_refsource_MISC
- lists.debian.org/debian-lts-announce/2021/08/msg00018.htmlmitremailing-listx_refsource_MLIST
News mentions
0No linked articles in our index yet.