CVE-2014-5271: Buffer Overflow
Heap-based buffer overflow in the encodeslice function in libavcodec/proresenckostya.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.x before 2.2.7, and 2.3.x before 2.3.3 and Libav before 10.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5271?
CVE-2014-5271 has a high severity rating due to the potential for remote code execution and denial of service.
How do I fix CVE-2014-5271?
To fix CVE-2014-5271, upgrade to FFmpeg version 1.1.14 or later, 1.2.8 or later, 2.2.7 or later, or 2.3.3 or later, or update to Libav version 10.5 or higher.
Which versions of FFmpeg are affected by CVE-2014-5271?
CVE-2014-5271 affects FFmpeg versions before 1.1.14, 1.2.x before 1.2.8, 2.x before 2.2.7, and 2.3.x before 2.3.3.
Which versions of Libav are affected by CVE-2014-5271?
CVE-2014-5271 affects Libav versions prior to 10.5.
What type of vulnerability is CVE-2014-5271?
CVE-2014-5271 is a heap-based buffer overflow vulnerability that can lead to crashes or remote code execution.