PT-2013-1094 · Debian+1 · Libav+1

Publicado

2013-11-23

·

Atualizado

2014-01-28

·

CVE-2013-0854

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libav versions prior to the fixed version
Description The issue concerns multiple vulnerabilities in the libav package of the Debian GNU/Linux operating system, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. Specifically, the mjpeg decode scan progressive ac function in libavcodec/mjpegdec.c in FFmpeg is affected, allowing remote attackers to have an impact via crafted MJPEG data.
Recommendations For versions prior to the fixed version, update to the fixed version to resolve the issue. As a temporary workaround, consider restricting access to the mjpeg decode scan progressive ac function in libavcodec/mjpegdec.c until a patch is available.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03049
CVE-2013-0854
DSA-2793-1

Produtos afetados

Ffmpeg
Libav