CVE-2013-7024: Buffer Overflow
The jpeg2000decodetile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not consider the component number in certain calculations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7024?
CVE-2013-7024 has been classified as having a moderate severity level since it can lead to a denial of service due to out-of-bounds array access.
How do I fix CVE-2013-7024?
To fix CVE-2013-7024, upgrade your FFmpeg installation to version 2.1 or later.
Which versions of FFmpeg are affected by CVE-2013-7024?
CVE-2013-7024 affects FFmpeg versions below 2.1, including all versions between 0.3 and 2.0.1.
What type of attack does CVE-2013-7024 enable?
CVE-2013-7024 enables denial of service attacks due to an out-of-bounds array access vulnerability.
Is there a workaround for CVE-2013-7024 if I cannot update FFmpeg?
Currently, there is no effective workaround for CVE-2013-7024 other than upgrading to a non-vulnerable version.