FFmpeg Multiple Vulnerabilities
Last Update Date:
9 Jul 2013 11:25
Release Date:
9 Jul 2013
3858
Views
RISK: Medium Risk
TYPE: Clients - Audio & Video
Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise an application using the library.
- An error within the "decode_subframe()" function (libavcodec/wmaprodec.c) can be exploited to cause a buffer overflow.
- An error within the "save_bits()" function (libavcodec/wmaprodec.c) when saving packets can be exploited to cause a buffer overflow.
- An error within the "ff_mjpeg_decode_frame()" function (libavcodec/mjpegdec.c) can be exploited to cause a buffer overflow.
- A NULL pointer dereference error exists within the "ivi_process_empty_tile()" function (libavcodec/ivi_common.c) and can be exploited to cause a crash.
- An error within the "decode_band()" function (libavcodec/ivi_common.c) when handling tile data can be exploited to corrupt memory.
- A NULL pointer dereference error exists within the "jpeg2000_decode_tile()" function (libavcodec/jpeg2000dec.c) and can be exploited to cause a crash.
- An out-of-bounds read error exists within the "jpeg2000_read_main_headers()" function (libavcodec/jpeg2000dec.c) when handling SOD markers and can be exploited to cause a crash.
- An out-of-bounds read error exists within the "ff_jpeg2000_init_component()" function (libavcodec/jpeg2000.c) and can be exploited to cause a crash.
- An out-of-bounds read error exists within the "get_cod()" function (libavcodec/jpeg2000dec.c) and can be exploited to cause a crash.
- An out-of-bounds read error within the get_coc()" function (libavcodec/jpeg2000dec.c) can be exploited to cause a crash.
- An out-of-bounds read error within the "get_qcc()" function (libavcodec/jpeg2000dec.c) can be exploited to cause a crash.
- An out-of-bounds read error within the "jpeg2000_read_main_headers()" function (libavcodec/jpeg2000dec.c) can be exploited to cause a crash.
Impact
- Denial of Service
System / Technologies affected
- FFmpeg 1.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Fixed in the GIT repository.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with