Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-12798
HistoryFeb 15, 2022 - 12:00 a.m.

ffjpeg Denial of Service Vulnerability (CNVD-2022-12798)

2022-02-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
13
ffjpeg
jpeg encoder/decoder
denial of service
vulnerability
cnvd-2022-12798
kai chen
china
bmp's metadata
memory buffer
program crash

EPSS

0.001

Percentile

40.0%

ffjpeg is a JPEG encoder/decoder by Kai Chen, a personal developer in China. ffjpeg suffers from a denial vulnerability that stems from when the size information in the bmp’s metadata is out of range, it returns without allocating a memory buffer to pb->pdata and without exiting the program. An attacker could exploit this vulnerability to cause the program to crash.

EPSS

0.001

Percentile

40.0%

Related for CNVD-2022-12798