FFmpeg · Ffmpeg · CVE-2013-7012
**Name of the Vulnerable Software and Affected Versions**
FFmpeg versions prior to 2.1
**Description**
The issue is related to the get siz function in libavcodec/jpeg2000dec.c, which does not prevent attempts to use non-zero image offsets. This allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data.
**Recommendations**
For versions prior to 2.1, update to version 2.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the get siz function in libavcodec/jpeg2000dec.c until a patch is available.