{"id":"CVE-2020-35965","details":"decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.","modified":"2026-04-16T00:04:23.375214345Z","published":"2021-01-04T02:15:11.273Z","related":["SUSE-SU-2021:3521-1","SUSE-SU-2023:0005-1","openSUSE-SU-2021:3521-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"last_affected":"10.0"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"9.0"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"}]},"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/01/msg00026.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202105-24"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-4990"},{"type":"REPORT","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26532"},{"type":"FIX","url":"https://github.com/FFmpeg/FFmpeg/commit/3e5959b3457f7f1856d997261e6ac672bba49e8b"},{"type":"FIX","url":"https://github.com/FFmpeg/FFmpeg/commit/b0a8b40294ea212c1938348ff112ef1b9bf16bb3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ffmpeg/ffmpeg","events":[{"introduced":"6b6b9e593dd4d3aaf75f48d40a13ef03bdef9fdb"},{"fixed":"c5079bf3bccd24bf8ed45ff47ff4071fd09e9fd8"},{"fixed":"3e5959b3457f7f1856d997261e6ac672bba49e8b"},{"fixed":"b0a8b40294ea212c1938348ff112ef1b9bf16bb3"}],"database_specific":{"extracted_events":[{"introduced":"4.3.1"},{"fixed":"4.4"}],"source":["CPE_FIELD","REFERENCES"],"cpe":"cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*"}}],"database_specific":{"vanir_signatures_modified":"2026-04-11T23:14:27Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","digest":{"function_hash":"124937820520588315441984477221866751122","length":3851},"source":"https://github.com/ffmpeg/ffmpeg/commit/3e5959b3457f7f1856d997261e6ac672bba49e8b","target":{"function":"decode_frame","file":"libavcodec/exr.c"},"id":"CVE-2020-35965-e8160555","deprecated":false},{"digest":{"line_hashes":["11453760296080827596215104085033325511","338685430887148091291965859791680091872","172064141470120326502547602228483699307","68840693532925938066564762591449107621"],"threshold":0.9},"signature_version":"v1","signature_type":"Line","source":"https://github.com/ffmpeg/ffmpeg/commit/3e5959b3457f7f1856d997261e6ac672bba49e8b","target":{"file":"libavcodec/exr.c"},"id":"CVE-2020-35965-fdcf59d3","deprecated":false}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-35965.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}