<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">Security update for ffmpeg</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2021:2322-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-07-14T15:03:30Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-07-14T15:03:30Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-07-14T15:03:30Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for ffmpeg</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for ffmpeg fixes the following issues:

- CVE-2020-13904: Fixed use-after-free via a crafted EXTINF duration in an m3u8 file (bsc#1172640).
- CVE-2020-21041: Fixed buffer overflow vulnerability via apng_do_inverse_blend in libavcodec/pngenc.c  (bsc#1186406).
- CVE-2019-17539: Fixed NULL pointer dereference in avcodec_open2 in libavcodec/utils.c (bsc# 1154065).
- CVE-2020-22026: Fixed buffer overflow vulnerability in config_input() at libavfilter/af_tremolo.c (bsc#1186583).
- CVE-2020-22021: Fixed buffer overflow vulnerability in filter_edges function in libavfilter/vf_yadif.c (bsc#1186586).
- CVE-2020-22020: Fixed buffer overflow vulnerability in build_diff_map() in libavfilter/vf_fieldmatch.c (bsc#1186587).
- CVE-2020-22015: Fixed buffer overflow vulnerability in mov_write_video_tag() due to the out of bounds in libavformat/movenc.c (bsc#1186596).
- CVE-2020-22016: Fixed a heap-based Buffer Overflow vulnerability at libavcodec/get_bits.h when writing .mov files (bsc#1186598).
- CVE-2020-22017: Fixed a heap-based Buffer Overflow vulnerability in ff_fill_rectangle() in libavfilter/drawutils.c (bsc#1186600).
- CVE-2020-22022: Fixed a heap-based Buffer Overflow vulnerability in filter_frame at libavfilter/vf_fieldorder.c (bsc#1186603).
- CVE-2020-22023: Fixed a heap-based Buffer Overflow vulnerability in filter_frame at libavfilter/vf_bitplanenoise.c (bsc#1186604)
- CVE-2020-22025: Fixed a heap-based Buffer Overflow vulnerability in gaussian_blur at libavfilter/vf_edgedetect.c (bsc#1186605).
- CVE-2020-22031: Fixed a heap-based Buffer Overflow vulnerability at libavfilter/vf_w3fdif.c in filter16_complex_low() (bsc#1186613).
- CVE-2020-22032: Fixed a heap-based Buffer Overflow vulnerability at libavfilter/vf_edgedetect.c in gaussian_blur() (bsc#1186614).
- CVE-2020-22034: Fixed a heap-based Buffer Overflow vulnerability at libavfilter/vf_floodfill.c (bsc#1186616).
- CVE-2020-20451: Fixed denial of service issue due to resource management errors via fftools/cmdutils.c (bsc#1186658).
- CVE-2020-20448: Fixed divide by zero issue via libavcodec/ratecontrol.c (bsc#1186660).
- CVE-2020-22038: Fixed denial of service vulnerability due to a memory leak in the ff_v4l2_m2m_create_context function in v4l2_m2m.c (bsc#1186757).
- CVE-2020-22039: Fixed denial of service vulnerability due to a memory leak in the inavi_add_ientry function (bsc#1186758).
- CVE-2020-22043: Fixed denial of service vulnerability due to a memory leak at the fifo_alloc_common function in libavutil/fifo.c (bsc#1186762).
- CVE-2020-22044: Fixed denial of service vulnerability due to a memory leak in the url_open_dyn_buf_internal function in libavformat/aviobuf.c (bsc#1186763).
- CVE-2020-22033,CVE-2020-22019: Fixed a heap-based Buffer Overflow Vulnerability at libavfilter/vf_vmafmotion.c in convolution_y_8bit() and in convolution_y_10bit() in libavfilter/vf_vmafmotion.c (bsc#1186615, bsc#1186597).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-SLE-15.3-2021-2322</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      <Description>E-Mail link for openSUSE-SU-2021:2322-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1172640</URL>
      <Description>SUSE Bug 1172640</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186406</URL>
      <Description>SUSE Bug 1186406</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186583</URL>
      <Description>SUSE Bug 1186583</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186586</URL>
      <Description>SUSE Bug 1186586</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186587</URL>
      <Description>SUSE Bug 1186587</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186596</URL>
      <Description>SUSE Bug 1186596</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186597</URL>
      <Description>SUSE Bug 1186597</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186598</URL>
      <Description>SUSE Bug 1186598</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186600</URL>
      <Description>SUSE Bug 1186600</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186603</URL>
      <Description>SUSE Bug 1186603</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186604</URL>
      <Description>SUSE Bug 1186604</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186605</URL>
      <Description>SUSE Bug 1186605</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186613</URL>
      <Description>SUSE Bug 1186613</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186614</URL>
      <Description>SUSE Bug 1186614</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186615</URL>
      <Description>SUSE Bug 1186615</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186616</URL>
      <Description>SUSE Bug 1186616</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186658</URL>
      <Description>SUSE Bug 1186658</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186660</URL>
      <Description>SUSE Bug 1186660</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186757</URL>
      <Description>SUSE Bug 1186757</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186758</URL>
      <Description>SUSE Bug 1186758</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186762</URL>
      <Description>SUSE Bug 1186762</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186763</URL>
      <Description>SUSE Bug 1186763</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-17539/</URL>
      <Description>SUSE CVE CVE-2019-17539 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-13904/</URL>
      <Description>SUSE CVE CVE-2020-13904 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-20448/</URL>
      <Description>SUSE CVE CVE-2020-20448 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-20451/</URL>
      <Description>SUSE CVE CVE-2020-20451 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-21041/</URL>
      <Description>SUSE CVE CVE-2020-21041 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22015/</URL>
      <Description>SUSE CVE CVE-2020-22015 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22016/</URL>
      <Description>SUSE CVE CVE-2020-22016 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22017/</URL>
      <Description>SUSE CVE CVE-2020-22017 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22019/</URL>
      <Description>SUSE CVE CVE-2020-22019 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22020/</URL>
      <Description>SUSE CVE CVE-2020-22020 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22021/</URL>
      <Description>SUSE CVE CVE-2020-22021 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22022/</URL>
      <Description>SUSE CVE CVE-2020-22022 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22023/</URL>
      <Description>SUSE CVE CVE-2020-22023 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22025/</URL>
      <Description>SUSE CVE CVE-2020-22025 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22026/</URL>
      <Description>SUSE CVE CVE-2020-22026 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22031/</URL>
      <Description>SUSE CVE CVE-2020-22031 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22032/</URL>
      <Description>SUSE CVE CVE-2020-22032 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22033/</URL>
      <Description>SUSE CVE CVE-2020-22033 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22034/</URL>
      <Description>SUSE CVE CVE-2020-22034 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22038/</URL>
      <Description>SUSE CVE CVE-2020-22038 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22039/</URL>
      <Description>SUSE CVE CVE-2020-22039 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22043/</URL>
      <Description>SUSE CVE CVE-2020-22043 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22044/</URL>
      <Description>SUSE CVE CVE-2020-22044 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="openSUSE Leap 15.3">
      <Branch Type="Product Name" Name="openSUSE Leap 15.3">
        <FullProductName ProductID="openSUSE Leap 15.3" CPE="cpe:/o:opensuse:leap:15.3">openSUSE Leap 15.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ffmpeg-3.4.2-11.3.1">
      <FullProductName ProductID="ffmpeg-3.4.2-11.3.1">ffmpeg-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ffmpeg-private-devel-3.4.2-11.3.1">
      <FullProductName ProductID="ffmpeg-private-devel-3.4.2-11.3.1">ffmpeg-private-devel-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec-devel-3.4.2-11.3.1">
      <FullProductName ProductID="libavcodec-devel-3.4.2-11.3.1">libavcodec-devel-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec57-3.4.2-11.3.1">
      <FullProductName ProductID="libavcodec57-3.4.2-11.3.1">libavcodec57-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec57-32bit-3.4.2-11.3.1">
      <FullProductName ProductID="libavcodec57-32bit-3.4.2-11.3.1">libavcodec57-32bit-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice-devel-3.4.2-11.3.1">
      <FullProductName ProductID="libavdevice-devel-3.4.2-11.3.1">libavdevice-devel-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice57-3.4.2-11.3.1">
      <FullProductName ProductID="libavdevice57-3.4.2-11.3.1">libavdevice57-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice57-32bit-3.4.2-11.3.1">
      <FullProductName ProductID="libavdevice57-32bit-3.4.2-11.3.1">libavdevice57-32bit-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter-devel-3.4.2-11.3.1">
      <FullProductName ProductID="libavfilter-devel-3.4.2-11.3.1">libavfilter-devel-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter6-3.4.2-11.3.1">
      <FullProductName ProductID="libavfilter6-3.4.2-11.3.1">libavfilter6-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter6-32bit-3.4.2-11.3.1">
      <FullProductName ProductID="libavfilter6-32bit-3.4.2-11.3.1">libavfilter6-32bit-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat-devel-3.4.2-11.3.1">
      <FullProductName ProductID="libavformat-devel-3.4.2-11.3.1">libavformat-devel-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat57-3.4.2-11.3.1">
      <FullProductName ProductID="libavformat57-3.4.2-11.3.1">libavformat57-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat57-32bit-3.4.2-11.3.1">
      <FullProductName ProductID="libavformat57-32bit-3.4.2-11.3.1">libavformat57-32bit-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample-devel-3.4.2-11.3.1">
      <FullProductName ProductID="libavresample-devel-3.4.2-11.3.1">libavresample-devel-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample3-3.4.2-11.3.1">
      <FullProductName ProductID="libavresample3-3.4.2-11.3.1">libavresample3-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample3-32bit-3.4.2-11.3.1">
      <FullProductName ProductID="libavresample3-32bit-3.4.2-11.3.1">libavresample3-32bit-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil-devel-3.4.2-11.3.1">
      <FullProductName ProductID="libavutil-devel-3.4.2-11.3.1">libavutil-devel-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil55-3.4.2-11.3.1">
      <FullProductName ProductID="libavutil55-3.4.2-11.3.1">libavutil55-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil55-32bit-3.4.2-11.3.1">
      <FullProductName ProductID="libavutil55-32bit-3.4.2-11.3.1">libavutil55-32bit-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc-devel-3.4.2-11.3.1">
      <FullProductName ProductID="libpostproc-devel-3.4.2-11.3.1">libpostproc-devel-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc54-3.4.2-11.3.1">
      <FullProductName ProductID="libpostproc54-3.4.2-11.3.1">libpostproc54-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc54-32bit-3.4.2-11.3.1">
      <FullProductName ProductID="libpostproc54-32bit-3.4.2-11.3.1">libpostproc54-32bit-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample-devel-3.4.2-11.3.1">
      <FullProductName ProductID="libswresample-devel-3.4.2-11.3.1">libswresample-devel-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample2-3.4.2-11.3.1">
      <FullProductName ProductID="libswresample2-3.4.2-11.3.1">libswresample2-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample2-32bit-3.4.2-11.3.1">
      <FullProductName ProductID="libswresample2-32bit-3.4.2-11.3.1">libswresample2-32bit-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale-devel-3.4.2-11.3.1">
      <FullProductName ProductID="libswscale-devel-3.4.2-11.3.1">libswscale-devel-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale4-3.4.2-11.3.1">
      <FullProductName ProductID="libswscale4-3.4.2-11.3.1">libswscale4-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale4-32bit-3.4.2-11.3.1">
      <FullProductName ProductID="libswscale4-32bit-3.4.2-11.3.1">libswscale4-32bit-3.4.2-11.3.1</FullProductName>
    </Branch>
    <Relationship ProductReference="ffmpeg-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1">ffmpeg-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="ffmpeg-private-devel-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1">ffmpeg-private-devel-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec-devel-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1">libavcodec-devel-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec57-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1">libavcodec57-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec57-32bit-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1">libavcodec57-32bit-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice-devel-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1">libavdevice-devel-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice57-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1">libavdevice57-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice57-32bit-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1">libavdevice57-32bit-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter-devel-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1">libavfilter-devel-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter6-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1">libavfilter6-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter6-32bit-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1">libavfilter6-32bit-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat-devel-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1">libavformat-devel-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat57-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1">libavformat57-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat57-32bit-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1">libavformat57-32bit-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample-devel-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1">libavresample-devel-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample3-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1">libavresample3-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample3-32bit-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1">libavresample3-32bit-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil-devel-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1">libavutil-devel-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil55-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1">libavutil55-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil55-32bit-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1">libavutil55-32bit-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc-devel-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1">libpostproc-devel-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc54-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1">libpostproc54-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc54-32bit-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1">libpostproc54-32bit-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample-devel-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1">libswresample-devel-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample2-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1">libswresample2-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample2-32bit-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1">libswresample2-32bit-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale-devel-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1">libswscale-devel-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale4-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1">libswscale4-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale4-32bit-3.4.2-11.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1">libswscale4-32bit-3.4.2-11.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
  </ProductTree>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified other impact when there is no valid close function pointer.</Note>
    </Notes>
    <CVE>CVE-2019-17539</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>7.5</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>3.3</BaseScoreV3>
        <VectorV3>CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-17539.html</URL>
        <Description>CVE-2019-17539</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1154065</URL>
        <Description>SUSE Bug 1154065</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_input_format3 in libavformat/format.c.</Note>
    </Notes>
    <CVE>CVE-2020-13904</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.4</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-13904.html</URL>
        <Description>CVE-2020-13904</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1172640</URL>
        <Description>SUSE Bug 1172640</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">FFmpeg 4.1.3 is affected by a Divide By Zero issue via libavcodec/ratecontrol.c, which allows a remote malicious user to cause a Denial of Service.</Note>
    </Notes>
    <CVE>CVE-2020-20448</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:S/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-20448.html</URL>
        <Description>CVE-2020-20448</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186660</URL>
        <Description>SUSE Bug 1186660</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c.</Note>
    </Notes>
    <CVE>CVE-2020-20451</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>5</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-20451.html</URL>
        <Description>CVE-2020-20451</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186658</URL>
        <Description>SUSE Bug 1186658</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Buffer Overflow vulnerability exists in FFmpeg 4.1 via apng_do_inverse_blend in libavcodec/pngenc.c, which could let a remote malicious user cause a Denial of Service</Note>
    </Notes>
    <CVE>CVE-2020-21041</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>5</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7.8</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-21041.html</URL>
        <Description>CVE-2020-21041</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186406</URL>
        <Description>SUSE Bug 1186406</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.</Note>
    </Notes>
    <CVE>CVE-2020-22015</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22015.html</URL>
        <Description>CVE-2020-22015</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186596</URL>
        <Description>SUSE Bug 1186596</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A heap-based Buffer Overflow vulnerability in FFmpeg 4.2 at libavcodec/get_bits.h when writing .mov files, which might lead to memory corruption and other potential consequences.</Note>
    </Notes>
    <CVE>CVE-2020-22016</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>3.3</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22016.html</URL>
        <Description>CVE-2020-22016</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186598</URL>
        <Description>SUSE Bug 1186598</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at ff_fill_rectangle in libavfilter/drawutils.c, which might lead to memory corruption and other potential consequences.</Note>
    </Notes>
    <CVE>CVE-2020-22017</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22017.html</URL>
        <Description>CVE-2020-22017</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186600</URL>
        <Description>SUSE Bug 1186600</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Buffer Overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilter/vf_vmafmotion.c, which could let a remote malicious user cause a Denial of Service.</Note>
    </Notes>
    <CVE>CVE-2020-22019</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22019.html</URL>
        <Description>CVE-2020-22019</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186597</URL>
        <Description>SUSE Bug 1186597</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Buffer Overflow vulnerability in FFmpeg 4.2 in the build_diff_map function in libavfilter/vf_fieldmatch.c, which could let a remote malicious user cause a Denial of Service.</Note>
    </Notes>
    <CVE>CVE-2020-22020</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22020.html</URL>
        <Description>CVE-2020-22020</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186587</URL>
        <Description>SUSE Bug 1186587</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Buffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function in libavfilter/vf_yadif.c, which could let a remote malicious user cause a Denial of Service.</Note>
    </Notes>
    <CVE>CVE-2020-22021</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22021.html</URL>
        <Description>CVE-2020-22021</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186586</URL>
        <Description>SUSE Bug 1186586</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_fieldorder.c, which might lead to memory corruption and other potential consequences.</Note>
    </Notes>
    <CVE>CVE-2020-22022</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22022.html</URL>
        <Description>CVE-2020-22022</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186603</URL>
        <Description>SUSE Bug 1186603</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A heap-based Buffer Overflow vulnerabililty exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_bitplanenoise.c, which might lead to memory corruption and other potential consequences.</Note>
    </Notes>
    <CVE>CVE-2020-22023</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22023.html</URL>
        <Description>CVE-2020-22023</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186604</URL>
        <Description>SUSE Bug 1186604</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A heap-based Buffer Overflow vulnerability exists in gaussian_blur at libavfilter/vf_edgedetect.c, which might lead to memory corruption and other potential consequences.</Note>
    </Notes>
    <CVE>CVE-2020-22025</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22025.html</URL>
        <Description>CVE-2020-22025</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186605</URL>
        <Description>SUSE Bug 1186605</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Buffer Overflow vulnerability exists in FFmpeg 4.2 in the config_input function at libavfilter/af_tremolo.c, which could let a remote malicious user cause a Denial of Service.</Note>
    </Notes>
    <CVE>CVE-2020-22026</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22026.html</URL>
        <Description>CVE-2020-22026</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186583</URL>
        <Description>SUSE Bug 1186583</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A Heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_w3fdif.c in filter16_complex_low, which might lead to memory corruption and other potential consequences.</Note>
    </Notes>
    <CVE>CVE-2020-22031</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22031.html</URL>
        <Description>CVE-2020-22031</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186613</URL>
        <Description>SUSE Bug 1186613</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_edgedetect.c in gaussian_blur, which might lead to memory corruption and other potential consequences.</Note>
    </Notes>
    <CVE>CVE-2020-22032</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22032.html</URL>
        <Description>CVE-2020-22032</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186614</URL>
        <Description>SUSE Bug 1186614</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vf_vmafmotion.c in convolution_y_8bit, which could let a remote malicious user cause a Denial of Service.</Note>
    </Notes>
    <CVE>CVE-2020-22033</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22033.html</URL>
        <Description>CVE-2020-22033</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186615</URL>
        <Description>SUSE Bug 1186615</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A heap-based Buffer Overflow vulnerability exists FFmpeg 4.2 at libavfilter/vf_floodfill.c, which might lead to memory corruption and other potential consequences.</Note>
    </Notes>
    <CVE>CVE-2020-22034</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22034.html</URL>
        <Description>CVE-2020-22034</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186616</URL>
        <Description>SUSE Bug 1186616</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_v4l2_m2m_create_context function in v4l2_m2m.c.</Note>
    </Notes>
    <CVE>CVE-2020-22038</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22038.html</URL>
        <Description>CVE-2020-22038</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186757</URL>
        <Description>SUSE Bug 1186757</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the inavi_add_ientry function.</Note>
    </Notes>
    <CVE>CVE-2020-22039</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22039.html</URL>
        <Description>CVE-2020-22039</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186758</URL>
        <Description>SUSE Bug 1186758</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="22">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak at the fifo_alloc_common function in libavutil/fifo.c.</Note>
    </Notes>
    <CVE>CVE-2020-22043</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22043.html</URL>
        <Description>CVE-2020-22043</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186762</URL>
        <Description>SUSE Bug 1186762</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="23">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the url_open_dyn_buf_internal function in libavformat/aviobuf.c.</Note>
    </Notes>
    <CVE>CVE-2020-22044</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MM55YS6XXAKFK3J35CDODMYMAZO6JX3S/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22044.html</URL>
        <Description>CVE-2020-22044</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186763</URL>
        <Description>SUSE Bug 1186763</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
</cvrfdoc>
