CVE-2013-7016: Buffer Overflow
The getsiz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the expected sample separation, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7016?
CVE-2013-7016 has a severity rating that can lead to denial of service due to out-of-bounds array access.
How do I fix CVE-2013-7016?
To mitigate CVE-2013-7016, upgrade to FFmpeg version 2.1 or later.
What versions of FFmpeg are affected by CVE-2013-7016?
CVE-2013-7016 affects all FFmpeg versions prior to 2.1, including several 0.x and 1.x versions.
What type of attack does CVE-2013-7016 facilitate?
CVE-2013-7016 allows remote attackers to exploit crafted JPEG2000 data, potentially leading to application crashes.
Is CVE-2013-7016 a widespread vulnerability?
While CVE-2013-7016 affects numerous versions of FFmpeg, the actual impact depends on the specific usage of FFmpeg in applications.