CVE Database
/

CVE-2021-3566

Back to search

CVE-2021-3566

Published: Aug 5, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that references an image, followed by a file the triggers the tty demuxer, the contents of the second file will be copied into the output file verbatim (as long as the `-vcodec copy` option is passed to ffmpeg).

VendorProductVersions

n/a

ffmpeg

affected
ffmpeg 4.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now