PT-2013-2690 · Libavcodec+2 · Libavcodec+2
Published
2013-02-21
·
Updated
2024-06-15
·
CVE-2013-0894
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions through 1.1.3
libavcodec versions through 1.1.3
Google Chrome versions before 25.0.1364.97 on Windows and Linux
Google Chrome versions before 25.0.1364.99 on Mac OS X
Description
The issue is related to a buffer overflow in the
vorbis parse setup hdr floors function in the Vorbis decoder. This can be exploited by remote attackers to cause a denial of service, such as a divide-by-zero error or out-of-bounds array access, via vectors involving a zero value for a bark map size.Recommendations
For FFmpeg versions through 1.1.3, update to a version later than 1.1.3 to resolve the issue.
For libavcodec versions through 1.1.3, update to a version later than 1.1.3 to resolve the issue.
For Google Chrome versions before 25.0.1364.97 on Windows and Linux, update to version 25.0.1364.97 or later to resolve the issue.
For Google Chrome versions before 25.0.1364.99 on Mac OS X, update to version 25.0.1364.99 or later to resolve the issue.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ffmpeg
Google Chrome
Libavcodec