CVE-2012-0849: Integer Overflow
Integer overflow in the ffj2kdwtinit function in libavcodec/j2kdwt.c in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted JPEG2000 image that triggers an incorrect check for a negative value.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0849?
The severity of CVE-2012-0849 is considered medium due to its potential to cause a denial of service through application crashes.
How do I fix CVE-2012-0849?
To fix CVE-2012-0849, upgrade to FFmpeg version 0.9.1 or later.
What causes CVE-2012-0849?
CVE-2012-0849 is caused by an integer overflow in the ff_j2k_dwt_init function when processing crafted JPEG2000 images.
Which versions of FFmpeg are affected by CVE-2012-0849?
All FFmpeg versions prior to 0.9.1, including versions 0.3 through 0.8.11, are affected by CVE-2012-0849.
Can CVE-2012-0849 be exploited remotely?
Yes, CVE-2012-0849 can be exploited remotely by attackers using specially crafted JPEG2000 images to trigger a crash.