First published: Wed Nov 05 2014(Updated: )
libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted JV data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | <=2.4.1 | |
Ubuntu Linux | =12.04 | |
Debian GNU/Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8542 is classified as a denial of service vulnerability due to out-of-bounds access.
To fix CVE-2014-8542, upgrade FFmpeg to version 2.4.2 or later.
CVE-2014-8542 affects FFmpeg versions prior to 2.4.2, Ubuntu 12.04, and Debian GNU/Linux 8.0.
The potential impacts of CVE-2014-8542 include remote denial of service through out-of-bounds access and possibly other unspecified consequences.
Yes, CVE-2014-8542 can be exploited remotely through crafted JV data.