PT-2015-2777 · FFmpeg · Ffmpeg

Published

2015-05-18

·

Updated

2019-03-31

·

CVE-2015-1872

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to 2.5.4
Description The issue is related to the ff mjpeg decode sof function in libavcodec/mjpegdec.c, which does not validate the number of components in a JPEG-LS Start Of Frame segment. This allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Motion JPEG data. The vulnerability can be exploited by a remote attacker using specially formed Motion JPEG data, leading to a denial of service.
Recommendations For versions prior to 2.5.4, update to version 2.5.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the ff mjpeg decode sof function until a patch is available. Avoid using crafted Motion JPEG data that could exploit the vulnerability.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-12142
CVE-2015-1872
DLA-1740-1
DLA-644-1
MGASA-2015-0233
MGASA-2015-0245
USN-2944-1

Affected Products

Ffmpeg