CVE-2020-20451
Ffmpeg vulnerability analysis and mitigation

Overview

A Denial of Service vulnerability (CVE-2020-20451) was discovered in FFmpeg version 4.2. The vulnerability stems from resource management errors in the fftools/cmdutils.c file. This vulnerability was initially reported in August 2020 and was later addressed in various FFmpeg versions (FFmpeg Ticket, Debian Advisory).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The issue is classified under CWE-401 (Missing Release of Memory after Effective Lifetime). The vulnerability specifically involves memory management issues in the grow_array function within the fftools/cmdutils.c component (NVD).

Impact

The vulnerability can lead to a Denial of Service condition through resource management errors. When successfully exploited, it could cause the application to become unresponsive or crash, affecting the availability of FFmpeg services (Debian Advisory).

Mitigation and workarounds

The vulnerability has been fixed in multiple FFmpeg versions. For Debian 9 stretch, the fix was implemented in version 7:3.2.16-1+deb9u1. The permanent fix was committed by Andreas Rheinhardt with commit ID 21265f42ecb265debe9fec1dbfd0cb7de5a8aefb (Debian Advisory, FFmpeg Ticket).

Additional resources


SourceThis report was generated using AI

Related Ffmpeg vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-59734HIGH8.7
  • FfmpegFfmpeg
  • ffmpeg
NoYesOct 06, 2025
CVE-2025-59733HIGH8.7
  • FfmpegFfmpeg
  • ffmpeg
NoYesOct 06, 2025
CVE-2025-59732HIGH8.7
  • FfmpegFfmpeg
  • ffmpeg
NoYesOct 06, 2025
CVE-2025-7700MEDIUM5.3
  • FfmpegFfmpeg
  • libpostproc-devel
NoYesNov 07, 2025
CVE-2025-12343N/AN/A
  • FfmpegFfmpeg
  • ffmpeg
NoYesOct 28, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management