CVE 7.2 HIGH

Remote code execution via Heap Buffer Overflow in FFmpeg JPEG2000_CVE-2025-9951

7.2 / 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H

Description

A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.

Basic Information

ID CVE-2025-9951
Source Google
Published Sep 9, 2025 at 13:54
Modified Sep 9, 2025 at 14:20

Affected Product

Vendor FFmpeg
Product FFmpeg
Version < 8.0
Affected Versions FFmpeg FFmpeg < 8.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.