cbsjpegsplitfragment in libavcodec/cbsjpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEGMARKERSOS handling because of a missing length check.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "ffmpeg" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavcodec-dev" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavcodec-extra" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavcodec-extra58" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavcodec58" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavdevice-dev" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavdevice58" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavfilter-dev" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavfilter-extra" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavfilter-extra7" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavfilter7" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavformat-dev" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavformat58" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavresample-dev" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavresample4" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavutil-dev" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libavutil56" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libpostproc-dev" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libpostproc55" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libswresample-dev" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libswresample3" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libswscale-dev" }, { "binary_version": "7:4.2.4-1ubuntu0.1", "binary_name": "libswscale5" } ] }