CVE-2013-0858
published 2013-12-07CVE-2013-0858: The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the…
PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.12%
86.5th percentile
The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer than two channels.
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 1.0.3 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-0858: ffmpeg - The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 al...
vendor_debian·2013·CVSS 9.3
CVE-2013-0858 [CRITICAL] CVE-2013-0858: ffmpeg - The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 al...
The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer than two channels.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-8mjg-4mv3-r39f: The atrac3_decode_init function in libavcodec/atrac3
ghsa_unreviewed·2022-05-17
CVE-2013-0858 [HIGH] GHSA-8mjg-4mv3-r39f: The atrac3_decode_init function in libavcodec/atrac3
The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer than two channels.
OSV
CVE-2013-0858: The atrac3_decode_init function in libavcodec/atrac3
osv·2013-12-07·CVSS 9.3
CVE-2013-0858 [CRITICAL] CVE-2013-0858: The atrac3_decode_init function in libavcodec/atrac3
The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer than two channels.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=13451f5520ce6b0afde861b2285dda659f8d4fb4http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=2502914c5f8eb77659d7c0868396862557a63245http://www.debian.org/security/2013/dsa-2793http://www.ffmpeg.org/security.htmlhttp://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=13451f5520ce6b0afde861b2285dda659f8d4fb4http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=2502914c5f8eb77659d7c0868396862557a63245http://www.debian.org/security/2013/dsa-2793http://www.ffmpeg.org/security.html
2013-12-07
Published