First published: Sat Jun 18 2022(Updated: )
A vulnerability classified as critical was found in FFmpeg 2.0. This vulnerability affects the function rpza_decode_stream. The manipulation leads to memory corruption. The attack can be initiated remotely. The name of the patch is Fixes Invalid Writes. It is recommended to apply a patch to fix this issue.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg FFmpeg | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-125017 is high.
CVE-2014-125017 affects FFmpeg version 2.0 by causing memory corruption in the rpza_decode_stream function.
Yes, CVE-2014-125017 can be initiated remotely.
You can find the patch for CVE-2014-125017 at http://git.videolan.org/?p=ffmpeg.git;a=commit;h=77bb0004bbe18f1498cfecdc68db5f10808b6599.
The Common Weakness Enumeration (CWE) ID for CVE-2014-125017 is CWE-125 and CWE-119.