Candidate: CVE-2012-0849 PublicDate: 2012-08-27 23:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0849 http://www.openwall.com/lists/oss-security/2012/02/14/4 Description: Integer overflow in the ff_j2k_dwt_init function in libavcodec/j2k_dwt.c in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted JPEG2000 image that triggers an incorrect check for a negative value. Ubuntu-Description: Notes: jdstrand> per upstream, j2k is marked as experimental mdeslaur> code not present in libav and ffmpeg 0.5.x Bugs: http://ffmpeg.org/trac/ffmpeg/ticket/776 Priority: low Discovered-by: Assigned-to: mdeslaur CVSS: Patches_ffmpeg: upstream: 1f99939a6361e2e6d6788494dd7c682b051c6c34 upstream_ffmpeg: needs-triage hardy_ffmpeg: ignored (reached end-of-life) lucid_ffmpeg: not-affected (code not present) maverick_ffmpeg: ignored (reached end-of-life) natty_ffmpeg: DNE oneiric_ffmpeg: DNE precise_ffmpeg: DNE devel_ffmpeg: DNE Patches_ffmpeg-extra: upstream_ffmpeg-extra: needs-triage hardy_ffmpeg-extra: DNE lucid_ffmpeg-extra: not-affected (code not present) maverick_ffmpeg-extra: ignored (reached end-of-life) natty_ffmpeg-extra: DNE oneiric_ffmpeg-extra: DNE precise_ffmpeg-extra: DNE devel_ffmpeg-extra: DNE Patches_libav: upstream_libav: not-affected hardy_libav: DNE lucid_libav: DNE maverick_libav: DNE natty_libav: not-affected (code not present) oneiric_libav: not-affected (code not present) precise_libav: not-affected (code not present) devel_libav: not-affected (code not present) Patches_libav-extra: upstream_libav-extra: needs-triage hardy_libav-extra: DNE lucid_libav-extra: DNE natty_libav-extra: not-affected (code not present) oneiric_libav-extra: not-affected (code not present) precise_libav-extra: not-affected (code not present) devel_libav-extra: not-affected (code not present)