In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfif.c. This is due to the incomplete patch for issue 38
Advisories
Source ID Title
EUVD EUVD EUVD-2022-32914 In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfif.c. This is due to the incomplete patch for issue 38
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T05:56:15.188Z

Reserved: 2022-04-04T00:00:00

Link: CVE-2022-28471

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-05T13:15:07.877

Modified: 2024-11-21T06:57:24.213

Link: CVE-2022-28471

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses