PT-2015-3158 · FFmpeg+1 · Ffmpeg+1
Publicado
2015-12-24
·
Atualizado
2018-12-21
·
CVE-2015-8662
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions prior to 2.8.4
Description
The issue arises from the
ff dwt decode function in libavcodec/jpeg2000dwt.c not validating the number of decomposition levels before proceeding with Discrete Wavelet Transform decoding. This allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data.Recommendations
For versions prior to 2.8.4, update to version 2.8.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
ff dwt decode function until a patch is available. Avoid using crafted JPEG 2000 data that could exploit this issue.Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ffmpeg
Suse