CVE-2013-7019: Input Validation
The getcox function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not properly validate the reduction factor, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7019?
CVE-2013-7019 has a medium severity rating as it can lead to denial of service.
How do I fix CVE-2013-7019?
To resolve CVE-2013-7019, upgrade to FFmpeg version 2.1 or later.
Which versions of FFmpeg are affected by CVE-2013-7019?
CVE-2013-7019 affects FFmpeg versions up to and including 2.0.1 and all versions starting from 0.3 up to 2.0.
What type of vulnerability is CVE-2013-7019?
CVE-2013-7019 is an out-of-bounds array access vulnerability that can be exploited by crafted JPEG2000 data.
Can CVE-2013-7019 lead to data loss?
While CVE-2013-7019 primarily results in denial of service, it could potentially be exploited in ways that may affect data integrity.