HIGH
FFmpeg rpza_decode_stream memory corruption
Published Jun 18, 2022
7.8
HIGHCVSS 3.1
EPSS 0.53%
Description
A vulnerability classified as critical was found in FFmpeg 2.0. This vulnerability affects the function rpza_decode_stream. The manipulation leads to memory corruption. The attack can be initiated remotely. The name of the patch is Fixes Invalid Writes. It is recommended to apply a patch to fix this issue.
Affected products
- Vendor n/a Product FFmpeg Defaultn/a
- Version 2.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | FFmpeg | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (2)
- http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=77bb0004bbe18f1498cfecdc68db5f10808b6599 x_refsource_MISC
- https://vuldb.com/?id.12340 x_refsource_MISCPermissions RequiredThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=77bb0004bbe18f1498cfecdc68db5f10808b6599 | x_refsource_MISC | |
| https://vuldb.com/?id.12340 | x_refsource_MISCPermissions RequiredThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jun 18, 2022
Updated Apr 15, 2025
Reserved Jun 17, 2022
Link CVE-2014-125017
CISA Vulnrichment
Updated Apr 14, 2025