VYPR
Unrated severityNVD Advisory· Published Mar 2, 2014· Updated Jun 17, 2026

CVE-2014-2097

CVE-2014-2097

Description

The tak_decode_frame function in libavcodec/takdec.c in FFmpeg before 2.1.4 does not properly validate a certain bits-per-sample value, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted TAK (aka Tom's lossless Audio Kompressor) data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • FFmpeg/Ffmpeg9 versions
    cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*range: <=2.1.3
    • cpe:2.3:a:ffmpeg:ffmpeg:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:2.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:2.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:2.1.2:*:*:*:*:*:*:*
    • (no CPE)range: <2.1.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.