CVE-2014-5272

libavcodec/iff.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.2.x before 2.2.7, and 2.3.x before 2.3.2 allows remote attackers to have unspecified impact via a crafted iff image, which triggers an out-of-bounds array access, related to the rgb8 and rgbn formats.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
VendorProductVersion
ffmpegffmpeg
𝑥
≤ 1.1.13
ffmpegffmpeg
1.1
ffmpegffmpeg
1.1.1
ffmpegffmpeg
1.1.2
ffmpegffmpeg
1.1.3
ffmpegffmpeg
1.1.4
ffmpegffmpeg
1.1.5
ffmpegffmpeg
1.1.6
ffmpegffmpeg
1.1.7
ffmpegffmpeg
1.1.8
ffmpegffmpeg
1.1.9
ffmpegffmpeg
1.1.10
ffmpegffmpeg
1.1.11
ffmpegffmpeg
1.1.12
ffmpegffmpeg
1.2
ffmpegffmpeg
1.2.1
ffmpegffmpeg
1.2.3
ffmpegffmpeg
1.2.4
ffmpegffmpeg
1.2.5
ffmpegffmpeg
1.2.6
ffmpegffmpeg
1.2.7
ffmpegffmpeg
2.0
ffmpegffmpeg
2.0.1
ffmpegffmpeg
2.0.2
ffmpegffmpeg
2.0.3
ffmpegffmpeg
2.0.4
ffmpegffmpeg
2.0.5
ffmpegffmpeg
2.1
ffmpegffmpeg
2.1.1
ffmpegffmpeg
2.1.2
ffmpegffmpeg
2.1.3
ffmpegffmpeg
2.1.4
ffmpegffmpeg
2.1.5
ffmpegffmpeg
2.2
ffmpegffmpeg
2.2.4
ffmpegffmpeg
2.3
ffmpegffmpeg
2.3.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ffmpeg
bullseye
7:4.3.7-0+deb11u1
fixed
bullseye (security)
7:4.3.8-0+deb11u1
fixed
bookworm
7:5.1.6-0+deb12u1
fixed
bookworm (security)
7:5.1.6-0+deb12u1
fixed
sid
7:7.1-3
fixed
trixie
7:7.1-3
fixed