Описание
A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| ffmpeg | unfixed | package | ||
| ffmpeg | postponed | trixie | package | |
| ffmpeg | postponed | bookworm | package | |
| ffmpeg | postponed | bullseye | package |
Примечания
https://github.com/google/security-research/security/advisories/GHSA-39q3-f8jq-v6mg
EPSS
Процентиль: 60%
0.004
Низкий
Связанные уязвимости
ubuntu
3 месяца назад
A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
nvd
3 месяца назад
A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
EPSS
Процентиль: 60%
0.004
Низкий