Your submission was sent successfully! Close

CVE-2015-8662

Published: 24 December 2015

The ff_dwt_decode function in libavcodec/jpeg2000dwt.c in FFmpeg before 2.8.4 does not validate the number of decomposition levels before proceeding with Discrete Wavelet Transform decoding, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data.

Priority

Medium

CVSS 3 base score: 7.3

Status

Package Release Status
ffmpeg
Launchpad, Ubuntu, Debian
artful Not vulnerable
(7:2.8.4-1ubuntu1)
bionic Not vulnerable
(7:2.8.4-1ubuntu1)
precise Does not exist

trusty Does not exist

upstream
Released (2.7.4,2.5.9)
vivid Not vulnerable
(7:2.5.9-0ubuntu0.15.04.1)
wily
Released (7:2.7.4-0ubuntu0.15.10.1)
xenial Not vulnerable
(7:2.8.4-1ubuntu1)
yakkety Not vulnerable
(7:2.8.4-1ubuntu1)
zesty Not vulnerable
(7:2.8.4-1ubuntu1)
libav
Launchpad, Ubuntu, Debian
artful Does not exist

bionic Does not exist

precise Does not exist
(precise was not-affected [code not present])
trusty Does not exist
(trusty was not-affected [code not present])
upstream Needs triage

vivid Ignored
(reached end-of-life)
wily Does not exist

xenial Does not exist

yakkety Does not exist

zesty Does not exist