Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-9316
HistoryDec 09, 2014 - 12:00 a.m.

CVE-2014-9316

2014-12-0900:00:00
ubuntu.com
ubuntu.com
22

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.006

Percentile

78.3%

The mjpeg_decode_app function in libavcodec/mjpegdec.c in FFMpeg before
2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers
to cause a denial of service (out-of-bounds heap access) and possibly have
other unspecified impact via vectors related to LJIF tags in an MJPEG file.

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.006

Percentile

78.3%