6.8
CVSSv2

CVE-2015-1872

Published: 26/07/2015 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The ff_mjpeg_decode_sof function in libavcodec/mjpegdec.c in FFmpeg prior to 2.5.4 does not validate the number of components in a JPEG-LS Start Of Frame segment, which allows remote malicious users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Motion JPEG data.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 12.04

ffmpeg ffmpeg

Vendor Advisories

Libav could be made to crash or run programs as your login if it opened a specially crafted file ...