CVE-2014-125003: FFmpeg jpeg2000dec.c get_siz memory corruption
Published Jun 18, 2022
·Updated
A vulnerability was found in FFmpeg 2.0 and classified as problematic. This issue affects the function getsiz of the file libavcodec/jpeg2000dec.c. The manipulation leads to memory corruption. The attack may be initiated remotely. It is recommended to apply a patch to fix this issue.
Affected Software
1 affected component
FFmpeg FFmpeg=2.0
Remediation
Event History
Jun 18, 2022
CVE Published
via MITRE·06:15 AM
Data Sourced
via MITRE·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2014-125003.
2
What is the severity rating of CVE-2014-125003?
The severity rating of CVE-2014-125003 is medium (5.5).
3
How does CVE-2014-125003 affect FFmpeg 2.0?
CVE-2014-125003 affects FFmpeg 2.0 by causing memory corruption in the get_siz function of libavcodec/jpeg2000dec.c.
4
Can CVE-2014-125003 be exploited remotely?
Yes, CVE-2014-125003 can be initiated remotely.
5
How can I fix CVE-2014-125003?
To fix CVE-2014-125003, it is recommended to apply a patch provided by FFmpeg.