PT-2022-7777 · FFmpeg · Ffmpeg
Gynvael Coldwind
+1
·
Published
2022-06-18
·
Updated
2022-06-27
·
CVE-2014-125017
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FFmpeg version 2.0
Description
A critical vulnerability was found in FFmpeg, affecting the
rpza decode stream function. This issue leads to memory corruption and can be initiated remotely. The patch, named Fixes Invalid Writes, is intended to resolve this problem.Recommendations
Apply the Fixes Invalid Writes patch to fix this issue. As a temporary workaround, consider disabling the
rpza decode stream function until the patch is applied.Fix
Out of bounds Read
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ffmpeg