#VU84800 Improper validation of array index in FFmpeg - CVE-2021-33815
Published: December 27, 2023
FFmpeg
ffmpeg.sourceforge.net
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to an out-of-bounds array access within the dwa_uncompress() function in libavcodec/exr.c. A remote attacker can trick the victim to open a specially crafted image, trigger memory corruption and execute arbitrary code on the system.