Описание
A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| ffmpeg | fixed | 7:7.1.2-1 | package | |
| ffmpeg | postponed | bullseye | package |
Примечания
https://github.com/google/security-research/security/advisories/GHSA-39q3-f8jq-v6mg
https://github.com/FFmpeg/FFmpeg/commit/01a292c7e36545ddeb3c7f79cd02e2611cd37d73 (n8.0)
https://github.com/FFmpeg/FFmpeg/commit/d141e864f73152e94e0c45cc4abb8c329275c265 (n7.1.2)
https://github.com/FFmpeg/FFmpeg/commit/1f03c050e4e37f96968d1ffa4d720ed20810fdf6 (n5.1.7)
EPSS
Связанные уязвимости
A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
Уязвимость компонента jpeg2000dec мультимедийной библиотеки FFmpeg, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании
EPSS