CVE-2014-2099: Ffmpeg

Medium severity, CVSS 6.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The msrle_decode_frame function in libavcodec/msrle.c in FFmpeg before 2.1.4 does not properly calculate line sizes, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Microsoft RLE video data.

Affected products

  • Ffmpeg Ffmpeg: up to and including 2.1.3; version 2.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.1 only; …

Published 2014-03-02. Last modified 2026-06-17.