CVE-2013-7018: Buffer Overflow
libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the use of valid code-block dimension values, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7018?
CVE-2013-7018 has been classified as a denial of service vulnerability due to out-of-bounds array access.
How do I fix CVE-2013-7018?
To fix CVE-2013-7018, update FFmpeg to version 2.1 or later, which addresses this vulnerability.
Which versions of FFmpeg are affected by CVE-2013-7018?
FFmpeg versions prior to 2.1, including multiple earlier versions such as 0.3 to 2.0.1, are affected by CVE-2013-7018.
What can CVE-2013-7018 allow attackers to do?
CVE-2013-7018 can allow remote attackers to cause a denial of service through crafted JPEG2000 data.
Is there any risk of data compromise with CVE-2013-7018?
CVE-2013-7018 primarily poses a denial of service risk, and the specific impact remains unspecified beyond this.