A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
CVSS Details
- CVSS 4.0 Base Score: 7.2 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ffmpeg | Dec 18, 2025 | Dec 18, 2025 |
| Ffmpeg | — | Upgrade to FFmpeg version 7.1.2Upgrade to FFmpeg version 8.0Upgrade to FFmpeg version 5.1.7 | Dec 5, 2025 | Sep 9, 2025 |
| Ubuntu | — | Upgrade libavcodec60 (Ubuntu Pro)Upgrade ffmpeg (Ubuntu Pro)Upgrade libavcodec57 (Ubuntu Pro)Upgrade libavformat60 (Ubuntu Pro)Upgrade libavformat57 (Ubuntu Pro)Upgrade libavformat58 (Ubuntu Pro)Upgrade libavcodec58 (Ubuntu Pro) | Oct 22, 2025 | Sep 9, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub