CVE-2014-8542

FFmpeg < 2.4.2 - Denial of Service via Crafted JV Data

Title source: llm
STIX 2.1

Description

libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted JV data.

References (5)

Core 5
Core References
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2534-1
Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/02/msg00005.html
Vendor Advisory x_refsource_confirm
http://www.ffmpeg.org/security.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201603-06

Scores

EPSS 0.0152
EPSS Percentile 81.5%

Details

CWE
CWE-119
Status published
Products (3)
canonical/ubuntu_linux 12.04
debian/debian_linux 8.0
ffmpeg/ffmpeg < 2.4.1
Published Nov 05, 2014
Tracked Since Feb 18, 2026