FFmpeg Denial of Service Vulnerability (CVE-2016-2213)
Publish date: 07 de abril de 2016
Gravedad: High
Identificadores de CVE : CVE-2016-2213
Fecha recomendada: 07 de abril de 2016
Descripción
The vulnerability found in jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.6 may allow remote attackers to cause a denial of service. It does this using a crafted JPEG 2000 data. Trend Micro researcher Lucas Leong is credited for discovery and reporting of this vulnerability.
Soluciones
Parche : https://www.ffmpeg.org/security.html
Software y versión afectados
- FFmpeg before 2.8.6