CVE-2020-22015: Debian Linux

High severity, CVSS 8.8. EPSS: 3.6% chance of exploitation in the next 30 days.

Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Ffmpeg Ffmpeg: version 4.2 only

Published 2021-05-26. Last modified 2026-06-17.