CVE-2020-14212
Ffmpeg vulnerability analysis and mitigation

Overview

FFmpeg through version 4.3 contains a heap-based buffer overflow vulnerability (CVE-2020-14212) in the avio_get_str function within libavformat/aviobuf.c. The vulnerability occurs because dnn_backend_native.c calls ff_dnn_load_model_native and omits a certain index check (CVE, Rapid7).

Technical details

The vulnerability is caused by a missing check of the operand_index variable while accessing network->operands and setting the name in dnn_backend_native.c. This leads to a heap-based buffer overflow in the avio_get_str function. The issue has a CVSS score of 7.0 (AV:N/AC:M/Au:N/C:P/I:P/A:P), indicating moderate severity with network vector attack potential (Rapid7).

Impact

The vulnerability could result in a read buffer overflow that may be used as a primitive to leak addresses or sensitive memory. This could potentially lead to arbitrary code execution or system crashes (FFmpeg Trac).

Exploitability

The vulnerability can be triggered through a specially crafted model file that exploits the missing index check. A proof of concept has been demonstrated using a manually crafted native model file that triggers the buffer overflow (FFmpeg Trac).

Mitigation and workarounds

The issue was fixed in FFmpeg version 4.2.4 and later releases. Users should upgrade to a patched version. The fix was implemented through a patch that adds proper index checking, as documented in the FFmpeg patchwork (Gentoo, FFmpeg Patchwork).

Additional resources


SourceThis report was generated using AI

Related Ffmpeg vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-70632HIGH8.5
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesAug 06, 2026
CVE-2026-70628HIGH8.5
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesAug 06, 2026
CVE-2026-70631MEDIUM6.8
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesAug 06, 2026
CVE-2026-70630MEDIUM6.8
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesAug 06, 2026
CVE-2026-70629MEDIUM6.8
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management