PT-2022-7777 · FFmpeg · Ffmpeg

Gynvael Coldwind

+1

·

Published

2022-06-18

·

Updated

2022-06-27

·

CVE-2014-125017

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg version 2.0
Description A critical vulnerability was found in FFmpeg, affecting the rpza decode stream function. This issue leads to memory corruption and can be initiated remotely. The patch, named Fixes Invalid Writes, is intended to resolve this problem.
Recommendations Apply the Fixes Invalid Writes patch to fix this issue. As a temporary workaround, consider disabling the rpza decode stream function until the patch is applied.

Fix

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-125017

Affected Products

Ffmpeg