Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2025-9951

Description

A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.

POC

Reference

- https://github.com/google/security-research/security/advisories/GHSA-39q3-f8jq-v6mg

Github

- https://github.com/ARPSyndicate/cve-scores

- https://github.com/fkie-cad/nvd-json-data-feeds