CVE-2020-13904 PUBLISHED

FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_input_format3 in libavformat/format.c.

EPSS 0.47% · 64.6th percentile

Risk Scores

EPSS Score
0.47%
64.6th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSffmpeg0, 7:3.3.4-2, 7:3.3.4-2build3
Ubuntu:16.04:LTSffmpeg7:2.8.15-0ubuntu0.16.04.1, *, 0
Ubuntu:20.04:LTSffmpeg7:4.1.4-1build2, 7:4.2.1-2, 7:4.2.1-2ubuntu1

Timeline

References

Open in Interactive Console →