PT-2021-7750 · Ffjpeg · Ffjpeg

Yangjiageng

·

Published

2021-05-18

·

Updated

2023-08-17

·

CVE-2020-23852

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ffjpeg versions through 2020-07-02
Description A heap-based buffer overflow issue exists in the jfif decode() function at ffjpeg/src/jfif.c (line 544 and line 545), which could cause a denial of service by submitting a malicious jpeg image. This issue is related to the jfif decode(void *ctxt, BMP *pb) function and may allow an attacker to cause a service disruption.
Recommendations For versions through 2020-07-02, consider disabling the jfif decode() function as a temporary workaround until a patch is available. Restrict access to the jfif.c module to minimize the risk of exploitation. Avoid using the jfif decode() function in the affected ffjpeg library until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-02428
CVE-2020-23852

Affected Products

Ffjpeg