First published: Mon Nov 03 2014(Updated: )
libavcodec/iff.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.2.x before 2.2.7, and 2.3.x before 2.3.2 allows remote attackers to have unspecified impact via a crafted iff image, which triggers an out-of-bounds array access, related to the rgb8 and rgbn formats.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | <=1.1.13 | |
FFmpeg | =1.1 | |
FFmpeg | =1.1.1 | |
FFmpeg | =1.1.2 | |
FFmpeg | =1.1.3 | |
FFmpeg | =1.1.4 | |
FFmpeg | =1.1.5 | |
FFmpeg | =1.1.6 | |
FFmpeg | =1.1.7 | |
FFmpeg | =1.1.8 | |
FFmpeg | =1.1.9 | |
FFmpeg | =1.1.10 | |
FFmpeg | =1.1.11 | |
FFmpeg | =1.1.12 | |
FFmpeg | =1.2 | |
FFmpeg | =1.2.1 | |
FFmpeg | =1.2.3 | |
FFmpeg | =1.2.4 | |
FFmpeg | =1.2.5 | |
FFmpeg | =1.2.6 | |
FFmpeg | =1.2.7 | |
FFmpeg | =2.0 | |
FFmpeg | =2.0.1 | |
FFmpeg | =2.0.2 | |
FFmpeg | =2.0.3 | |
FFmpeg | =2.0.4 | |
FFmpeg | =2.0.5 | |
FFmpeg | =2.1 | |
FFmpeg | =2.1.1 | |
FFmpeg | =2.1.2 | |
FFmpeg | =2.1.3 | |
FFmpeg | =2.1.4 | |
FFmpeg | =2.1.5 | |
FFmpeg | =2.2 | |
FFmpeg | =2.2.4 | |
FFmpeg | =2.3 | |
FFmpeg | =2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5272 is classified as a moderate severity vulnerability due to its potential for remote exploitation through crafted iff images.
To fix CVE-2014-5272, you should update your FFmpeg to version 1.1.14, 1.2.8, 2.2.7, or 2.3.2 or later.
Affected versions include FFmpeg before 1.1.14, 1.2.x before 1.2.8, 2.2.x before 2.2.7, and 2.3.x before 2.3.2.
Yes, CVE-2014-5272 allows remote attackers to exploit the vulnerability by sending crafted iff images.
CVE-2014-5272 may lead to out-of-bounds array access, which could potentially compromise the system's security.