Lucene search

K
cvelistVulDBCVELIST:CVE-2014-125017
HistoryJun 18, 2022 - 6:16 a.m.

CVE-2014-125017 FFmpeg rpza_decode_stream memory corruption

2022-06-1806:16:08
CWE-119
VulDB
www.cve.org
4
ffmpeg
memory corruption
vulnerability
cve-2014-125017
rpza_decode_stream
remote attack
patch
fixes invalid writes

CVSS3

7.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

EPSS

0.001

Percentile

24.2%

A vulnerability classified as critical was found in FFmpeg 2.0. This vulnerability affects the function rpza_decode_stream. The manipulation leads to memory corruption. The attack can be initiated remotely. The name of the patch is Fixes Invalid Writes. It is recommended to apply a patch to fix this issue.

CNA Affected

[
  {
    "product": "FFmpeg",
    "vendor": "unspecified",
    "versions": [
      {
        "status": "affected",
        "version": "2.0"
      }
    ]
  }
]

CVSS3

7.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

EPSS

0.001

Percentile

24.2%

Related for CVELIST:CVE-2014-125017