<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">Security update for ffmpeg</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2021:3521-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-10-26T13:39:27Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-10-26T13:39:27Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-10-26T13:39:27Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for ffmpeg</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for ffmpeg fixes the following issues:

- CVE-2021-3566: Fixed information leak (bsc#1189166).
- CVE-2021-38093: Fixed integer overflow vulnerability in filter_robert() (bsc#1190734)
- CVE-2021-38092: Fixed integer overflow vulnerability in filter_prewitt() (bsc#1190733)
- CVE-2021-38094: Fixed integer overflow vulnerability in filter_sobel() (bsc#1190735)
- CVE-2020-22037: Fixed denial of service vulnerability caused by memory leak in avcodec_alloc_context3() (bsc#1186756)
- CVE-2020-35965: Fixed out-of-bounds write in decode_frame() (bsc#1187852)
- CVE-2020-20892: Fixed an issue with filter_frame() (bsc#1190719)
- CVE-2020-20891: Fixed a buffer overflow vulnerability in config_input() (bsc#1190718)
- CVE-2020-20895: Fixed a buffer overflow vulnerability in function filter_vertically_##name (bsc#1190722)
- CVE-2020-20896: Fixed an issue with latm_write_packet() (bsc#1190723)
- CVE-2020-20899: Fixed a buffer overflow vulnerability in config_props() (bsc#1190726)
- CVE-2020-20902: Fixed an out-of-bounds read vulnerabilit long_term_filter() (bsc#1190729)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-SLE-15.3-2021-3521</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HVCB2YATP2LRWUBIGFYZQUFV52VSFT2B/</URL>
      <Description>E-Mail link for openSUSE-SU-2021:3521-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186756</URL>
      <Description>SUSE Bug 1186756</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1187852</URL>
      <Description>SUSE Bug 1187852</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1189166</URL>
      <Description>SUSE Bug 1189166</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1190718</URL>
      <Description>SUSE Bug 1190718</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1190719</URL>
      <Description>SUSE Bug 1190719</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1190722</URL>
      <Description>SUSE Bug 1190722</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1190723</URL>
      <Description>SUSE Bug 1190723</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1190726</URL>
      <Description>SUSE Bug 1190726</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1190729</URL>
      <Description>SUSE Bug 1190729</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1190733</URL>
      <Description>SUSE Bug 1190733</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1190734</URL>
      <Description>SUSE Bug 1190734</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1190735</URL>
      <Description>SUSE Bug 1190735</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-20891/</URL>
      <Description>SUSE CVE CVE-2020-20891 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-20892/</URL>
      <Description>SUSE CVE CVE-2020-20892 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-20895/</URL>
      <Description>SUSE CVE CVE-2020-20895 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-20896/</URL>
      <Description>SUSE CVE CVE-2020-20896 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-20899/</URL>
      <Description>SUSE CVE CVE-2020-20899 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-20902/</URL>
      <Description>SUSE CVE CVE-2020-20902 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-22037/</URL>
      <Description>SUSE CVE CVE-2020-22037 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-35965/</URL>
      <Description>SUSE CVE CVE-2020-35965 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3566/</URL>
      <Description>SUSE CVE CVE-2021-3566 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-38092/</URL>
      <Description>SUSE CVE CVE-2021-38092 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-38093/</URL>
      <Description>SUSE CVE CVE-2021-38093 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-38094/</URL>
      <Description>SUSE CVE CVE-2021-38094 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="openSUSE Leap 15.3">
      <Branch Type="Product Name" Name="openSUSE Leap 15.3">
        <FullProductName ProductID="openSUSE Leap 15.3" CPE="cpe:/o:opensuse:leap:15.3">openSUSE Leap 15.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ffmpeg-3.4.2-11.17.1">
      <FullProductName ProductID="ffmpeg-3.4.2-11.17.1">ffmpeg-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ffmpeg-private-devel-3.4.2-11.17.1">
      <FullProductName ProductID="ffmpeg-private-devel-3.4.2-11.17.1">ffmpeg-private-devel-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec-devel-3.4.2-11.17.1">
      <FullProductName ProductID="libavcodec-devel-3.4.2-11.17.1">libavcodec-devel-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec57-3.4.2-11.17.1">
      <FullProductName ProductID="libavcodec57-3.4.2-11.17.1">libavcodec57-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavcodec57-32bit-3.4.2-11.17.1">
      <FullProductName ProductID="libavcodec57-32bit-3.4.2-11.17.1">libavcodec57-32bit-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice-devel-3.4.2-11.17.1">
      <FullProductName ProductID="libavdevice-devel-3.4.2-11.17.1">libavdevice-devel-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice57-3.4.2-11.17.1">
      <FullProductName ProductID="libavdevice57-3.4.2-11.17.1">libavdevice57-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavdevice57-32bit-3.4.2-11.17.1">
      <FullProductName ProductID="libavdevice57-32bit-3.4.2-11.17.1">libavdevice57-32bit-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter-devel-3.4.2-11.17.1">
      <FullProductName ProductID="libavfilter-devel-3.4.2-11.17.1">libavfilter-devel-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter6-3.4.2-11.17.1">
      <FullProductName ProductID="libavfilter6-3.4.2-11.17.1">libavfilter6-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavfilter6-32bit-3.4.2-11.17.1">
      <FullProductName ProductID="libavfilter6-32bit-3.4.2-11.17.1">libavfilter6-32bit-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat-devel-3.4.2-11.17.1">
      <FullProductName ProductID="libavformat-devel-3.4.2-11.17.1">libavformat-devel-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat57-3.4.2-11.17.1">
      <FullProductName ProductID="libavformat57-3.4.2-11.17.1">libavformat57-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavformat57-32bit-3.4.2-11.17.1">
      <FullProductName ProductID="libavformat57-32bit-3.4.2-11.17.1">libavformat57-32bit-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample-devel-3.4.2-11.17.1">
      <FullProductName ProductID="libavresample-devel-3.4.2-11.17.1">libavresample-devel-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample3-3.4.2-11.17.1">
      <FullProductName ProductID="libavresample3-3.4.2-11.17.1">libavresample3-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavresample3-32bit-3.4.2-11.17.1">
      <FullProductName ProductID="libavresample3-32bit-3.4.2-11.17.1">libavresample3-32bit-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil-devel-3.4.2-11.17.1">
      <FullProductName ProductID="libavutil-devel-3.4.2-11.17.1">libavutil-devel-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil55-3.4.2-11.17.1">
      <FullProductName ProductID="libavutil55-3.4.2-11.17.1">libavutil55-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavutil55-32bit-3.4.2-11.17.1">
      <FullProductName ProductID="libavutil55-32bit-3.4.2-11.17.1">libavutil55-32bit-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc-devel-3.4.2-11.17.1">
      <FullProductName ProductID="libpostproc-devel-3.4.2-11.17.1">libpostproc-devel-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc54-3.4.2-11.17.1">
      <FullProductName ProductID="libpostproc54-3.4.2-11.17.1">libpostproc54-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpostproc54-32bit-3.4.2-11.17.1">
      <FullProductName ProductID="libpostproc54-32bit-3.4.2-11.17.1">libpostproc54-32bit-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample-devel-3.4.2-11.17.1">
      <FullProductName ProductID="libswresample-devel-3.4.2-11.17.1">libswresample-devel-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample2-3.4.2-11.17.1">
      <FullProductName ProductID="libswresample2-3.4.2-11.17.1">libswresample2-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswresample2-32bit-3.4.2-11.17.1">
      <FullProductName ProductID="libswresample2-32bit-3.4.2-11.17.1">libswresample2-32bit-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale-devel-3.4.2-11.17.1">
      <FullProductName ProductID="libswscale-devel-3.4.2-11.17.1">libswscale-devel-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale4-3.4.2-11.17.1">
      <FullProductName ProductID="libswscale4-3.4.2-11.17.1">libswscale4-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libswscale4-32bit-3.4.2-11.17.1">
      <FullProductName ProductID="libswscale4-32bit-3.4.2-11.17.1">libswscale4-32bit-3.4.2-11.17.1</FullProductName>
    </Branch>
    <Relationship ProductReference="ffmpeg-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:ffmpeg-3.4.2-11.17.1">ffmpeg-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="ffmpeg-private-devel-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.17.1">ffmpeg-private-devel-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec-devel-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.17.1">libavcodec-devel-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec57-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavcodec57-3.4.2-11.17.1">libavcodec57-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavcodec57-32bit-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.17.1">libavcodec57-32bit-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice-devel-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.17.1">libavdevice-devel-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice57-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavdevice57-3.4.2-11.17.1">libavdevice57-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavdevice57-32bit-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.17.1">libavdevice57-32bit-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter-devel-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.17.1">libavfilter-devel-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter6-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavfilter6-3.4.2-11.17.1">libavfilter6-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavfilter6-32bit-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.17.1">libavfilter6-32bit-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat-devel-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavformat-devel-3.4.2-11.17.1">libavformat-devel-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat57-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavformat57-3.4.2-11.17.1">libavformat57-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavformat57-32bit-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.17.1">libavformat57-32bit-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample-devel-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavresample-devel-3.4.2-11.17.1">libavresample-devel-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample3-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavresample3-3.4.2-11.17.1">libavresample3-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavresample3-32bit-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.17.1">libavresample3-32bit-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil-devel-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavutil-devel-3.4.2-11.17.1">libavutil-devel-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil55-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavutil55-3.4.2-11.17.1">libavutil55-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavutil55-32bit-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.17.1">libavutil55-32bit-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc-devel-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.17.1">libpostproc-devel-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc54-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libpostproc54-3.4.2-11.17.1">libpostproc54-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpostproc54-32bit-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.17.1">libpostproc54-32bit-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample-devel-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libswresample-devel-3.4.2-11.17.1">libswresample-devel-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample2-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libswresample2-3.4.2-11.17.1">libswresample2-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswresample2-32bit-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.17.1">libswresample2-32bit-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale-devel-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libswscale-devel-3.4.2-11.17.1">libswscale-devel-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale4-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libswscale4-3.4.2-11.17.1">libswscale4-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libswscale4-32bit-3.4.2-11.17.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.17.1">libswscale4-32bit-3.4.2-11.17.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
  </ProductTree>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Buffer Overflow vulnerability in function config_input in libavfilter/vf_gblur.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.</Note>
    </Notes>
    <CVE>CVE-2020-20891</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.17.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HVCB2YATP2LRWUBIGFYZQUFV52VSFT2B/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-20891.html</URL>
        <Description>CVE-2020-20891</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190718</URL>
        <Description>SUSE Bug 1190718</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in function filter_frame in libavfilter/vf_lenscorrection.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts due to a division by zero.</Note>
    </Notes>
    <CVE>CVE-2020-20892</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.17.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HVCB2YATP2LRWUBIGFYZQUFV52VSFT2B/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-20892.html</URL>
        <Description>CVE-2020-20892</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190719</URL>
        <Description>SUSE Bug 1190719</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-22028. Reason: This candidate is a duplicate of CVE-2020-22028. Notes: All CVE users should reference CVE-2020-22028 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.</Note>
    </Notes>
    <CVE>CVE-2020-20895</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.17.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HVCB2YATP2LRWUBIGFYZQUFV52VSFT2B/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-20895.html</URL>
        <Description>CVE-2020-20895</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190722</URL>
        <Description>SUSE Bug 1190722</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in function latm_write_packet in libavformat/latmenc.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts due to a Null pointer dereference.</Note>
    </Notes>
    <CVE>CVE-2020-20896</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.17.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HVCB2YATP2LRWUBIGFYZQUFV52VSFT2B/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-20896.html</URL>
        <Description>CVE-2020-20896</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190723</URL>
        <Description>SUSE Bug 1190723</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-22036. Reason: This candidate is a duplicate of CVE-2020-22036. Notes: All CVE users should reference CVE-2020-22036 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.</Note>
    </Notes>
    <CVE>CVE-2020-20899</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.17.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HVCB2YATP2LRWUBIGFYZQUFV52VSFT2B/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-20899.html</URL>
        <Description>CVE-2020-20899</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190726</URL>
        <Description>SUSE Bug 1190726</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A CWE-125: Out-of-bounds read vulnerability exists in long_term_filter function in g729postfilter.c in FFmpeg 4.2.1 during computation of the denominator of pseudo-normalized correlation R'(0), that could result in disclosure of information.</Note>
    </Notes>
    <CVE>CVE-2020-20902</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.17.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HVCB2YATP2LRWUBIGFYZQUFV52VSFT2B/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-20902.html</URL>
        <Description>CVE-2020-20902</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190729</URL>
        <Description>SUSE Bug 1190729</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.</Note>
    </Notes>
    <CVE>CVE-2020-22037</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.17.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HVCB2YATP2LRWUBIGFYZQUFV52VSFT2B/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-22037.html</URL>
        <Description>CVE-2020-22037</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186756</URL>
        <Description>SUSE Bug 1186756</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.</Note>
    </Notes>
    <CVE>CVE-2020-35965</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.17.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>5</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HVCB2YATP2LRWUBIGFYZQUFV52VSFT2B/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-35965.html</URL>
        <Description>CVE-2020-35965</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1187852</URL>
        <Description>SUSE Bug 1187852</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that references an image, followed by a file the triggers the tty demuxer, the contents of the second file will be copied into the output file verbatim (as long as the `-vcodec copy` option is passed to ffmpeg).</Note>
    </Notes>
    <CVE>CVE-2021-3566</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.17.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>4.4</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HVCB2YATP2LRWUBIGFYZQUFV52VSFT2B/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3566.html</URL>
        <Description>CVE-2021-3566</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1189166</URL>
        <Description>SUSE Bug 1189166</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer Overflow vulnerability in function filter_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.</Note>
    </Notes>
    <CVE>CVE-2021-38092</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.17.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HVCB2YATP2LRWUBIGFYZQUFV52VSFT2B/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-38092.html</URL>
        <Description>CVE-2021-38092</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190733</URL>
        <Description>SUSE Bug 1190733</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer Overflow vulnerability in function filter_robert in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.</Note>
    </Notes>
    <CVE>CVE-2021-38093</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.17.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HVCB2YATP2LRWUBIGFYZQUFV52VSFT2B/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-38093.html</URL>
        <Description>CVE-2021-38093</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190734</URL>
        <Description>SUSE Bug 1190734</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer Overflow vulnerability in function filter_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.</Note>
    </Notes>
    <CVE>CVE-2021-38094</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:ffmpeg-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ffmpeg-private-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavcodec57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavdevice57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavfilter6-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavformat57-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavresample3-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libavutil55-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libpostproc54-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswresample2-32bit-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale-devel-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-3.4.2-11.17.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libswscale4-32bit-3.4.2-11.17.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HVCB2YATP2LRWUBIGFYZQUFV52VSFT2B/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-38094.html</URL>
        <Description>CVE-2021-38094</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190735</URL>
        <Description>SUSE Bug 1190735</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
</cvrfdoc>
