VDB
GCVE-VVD-MAGEIA-2014-491
GCVE-VVD-MAGEIA-2014-491
Advisory Published
A heap-based buffer overflow in the encode_slice function in
libavcodec/proresenc_kostya.c in FFmpeg before 1.2.9 can cause a crash,
allowing a malicious image file to cause a denial of service (CVE-2014-5271).
libavcodec/iff.c in FFmpeg before 1.2.9 allows an attacker to have an
unspecified impact via a crafted iff image, which triggers an out-of-bounds
array access, related to the rgb8 and rgbn formats (CVE-2014-5272).
libavcodec/mjpegdec.c in FFmpeg before 1.2.9 considers only dimension
differences, and not bits-per-pixel differences, when determining whether an
image size has changed, which allows remote attackers to cause a denial of
service (out-of-bounds access) or possibly have unspecified other impact via
crafted MJPEG data (CVE-2014-8541).
libavcodec/utils.c in FFmpeg before 1.2.9 omits a certain codec ID during
enforcement of alignment, which allows remote attackers to cause a denial of
service (out-of-bounds access) or possibly have unspecified other impact via
crafted JV data (CVE-2014-8542).
libavcodec/mmvideo.c in FFmpeg before 1.2.9 does not consider all lines of
HHV Intra blocks during validation of image height, which allows remote
attackers to cause a denial of service (out-of-bounds access) or possibly
have unspecified other impact via crafted MM video data (CVE-2014-8543).
libavcodec/tiff.c in FFmpeg before 1.2.9 does not properly validate
bits-per-pixel fields, which allows remote attackers to cause a denial of
service (out-of-bounds access) or possibly have unspecified other impact via
crafted TIFF data (CVE-2014-8544).
libavcodec/pngdec.c in FFmpeg before 1.2.9 accepts the monochrome-black
format without verifying that the bits-per-pixel value is 1, which allows
remote attackers to cause a denial of service (out-of-bounds access) or
possibly have unspecified other impact via crafted PNG data (CVE-2014-8545).
Integer underflow in libavcodec/cinepak.c in FFmpeg before 1.2.9 allows
remote attackers to cause a denial of service (out-of-bounds access) or
possibly have unspecified other impact via crafted Cinepak video data
(CVE-2014-8546).
libavcodec/gifdec.c in FFmpeg before 1.2.9 does not properly compute image
heights, which allows remote attackers to cause a denial of service
(out-of-bounds access) or possibly have unspecified other impact via crafted
GIF data (CVE-2014-8547).
Off-by-one error in libavcodec/smc.c in FFmpeg before 1.2.9 allows remote
attackers to cause a denial of service (out-of-bounds access) or possibly
have unspecified other impact via crafted Quicktime Graphics (aka SMC) video
data (CVE-2014-8548).
Avidemux built with a bundled set of FFmpeg libraries. The bundled FFmpeg
version have been updated from 1.2.7 to 1.2.10 to fix these security issues
and other bugs fixed upstream in FFmpeg.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | avidemux | 0 (affected), 2.6.6-2.2.mga4 (unaffected), 0 (affected), 2.6.6-2.2.mga4.tainted (unaffected) | — |
Aliases
CVE-2014-8546CVE-2014-8541CVE-2014-5272CVE-2014-8547CVE-2014-5271CVE-2014-8542CVE-2014-8544CVE-2014-8545CVE-2014-8548CVE-2014-8543
Transitive aliases
GHSA-5mrc-xgr5-4v65GHSA-9323-4x78-29mvCVE-2011-3934GHSA-hjq3-qcx4-mc3mGHSA-7hj8-8pm2-g3w2GHSA-vfm7-qg4x-5fg2GHSA-498p-f88v-m654CVE-2016-3062GHSA-j4v2-7rrj-34pxVVD-MAGEIA-2015-245CVE-2011-3947GHSA-c3mp-24r8-cfj3GSD-2014-8542CVE-2012-6618CVE-2011-3944CVE-2013-7010GSD-2014-9317GSD-2014-9603GHSA-qcq8-x6c3-9rx4GSD-2014-5272GHSA-jj3j-75wc-9j9fGSD-2014-8545CVE-2011-3929GSD-2012-0853BDU:2015-12142GSD-2014-5271CVE-2011-3941GSD-2011-3936GSD-2011-3940VVD-MAGEIA-2014-473CVE-2015-3395GSD-2011-3947GHSA-94vc-jrg8-w47hGHSA-qmmw-8mm8-4p5gGHSA-54rc-7rpj-78x5CVE-2013-0852CVE-2011-3940CVE-2011-3937GSD-2011-3929CVE-2014-9318GHSA-gr7x-fxqg-h7mwGHSA-2m76-jw89-jx9cGHSA-vc6h-vvh3-6pm8GHSA-xwfp-hmj5-wfj5CVE-2014-9316GHSA-m97m-jg28-f9x7GSD-2014-8547GHSA-cwx4-37g9-wvw2GSD-2014-8546CVE-2011-3950GSD-2011-3951CVE-2014-9317CVE-2011-3936CVE-2011-3935GHSA-xrfr-h69f-r87qCVE-2013-0851VVD-MAGEIA-2015-233GHSA-8p7j-772c-jrhmOPENSUSE-SU-2024:10926-1CVE-2014-9604GHSA-8rm9-ph3p-x36xGHSA-jmx2-8qx7-7pc4GSD-2014-9318CVE-2011-3946GHSA-vxg7-m3mm-xp7qVVD-MAGEIA-2014-464CVE-2011-3952CVE-2012-0853GHSA-h56g-pfwx-x484CVE-2012-0858GHSA-rq6w-rq9c-3jhvGHSA-852r-wj69-22qjGHSA-5cmq-34ww-75f4GHSA-xjwf-x6xw-g8pfGHSA-cp5p-v2wm-v8hpCVE-2015-3417CVE-2011-3949CVE-2015-5479GSD-2013-0851CNVD-2015-00537GHSA-wwfj-h5pc-cmm2GHSA-m2wr-6c66-v8jjCVE-2014-9603GSD-2014-8543GSD-2011-3945CVE-2015-1872GHSA-q2r7-wvw8-54qrGSD-2014-8548GHSA-fmmw-c889-hg82GHSA-q8mw-vrp6-fqq8GSD-2015-1872GHSA-3f4q-ffp5-3396GHSA-xjr8-mfv3-96c3GHSA-h626-6f8j-9rc9GHSA-73wj-87qj-vf4xGHSA-g562-7r9w-rhjcCVE-2011-3951GHSA-2pg8-mr5w-rhvwCVE-2013-0868CVE-2011-3945GSD-2012-6618GSD-2012-0858GSD-2014-9316GSD-2014-8541GHSA-xjw3-xjhw-33xqCNVD-2015-01318
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.