Segmentation Violation in FFmpeg's JPEG2000 Decoder
CVE-2025-22921

6.5MEDIUM

Key Information:

Vendor

FFmpeg

Status
Vendor
CVE Published:
18 February 2025

What is CVE-2025-22921?

A segmentation violation has been identified in FFmpeg's JPEG2000 decoding module. This flaw can lead to unexpected behavior and potential application crashes when processing specially crafted JPEG2000 files. It is crucial for users and developers to apply necessary patches to mitigate associated risks to system stability and security.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.