PT-2013-2659 · FFmpeg · Ffmpeg

Published

2013-11-23

·

Updated

2016-12-03

·

CVE-2013-0860

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to 1.0.4 FFmpeg versions 1.1.x prior to 1.1.1
Description The issue arises from the ff er frame end function in libavcodec/error resilience.c, which fails to properly verify that a frame is fully initialized. This allows remote attackers to trigger a NULL pointer dereference via crafted picture data.
Recommendations For FFmpeg versions prior to 1.0.4, update to version 1.0.4 or later. For FFmpeg versions 1.1.x prior to 1.1.1, update to version 1.1.1 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0860
DSA-3003-1

Affected Products

Ffmpeg