CVE-2013-0861Improper Restriction of Operations within the Bounds of a Memory Buffer in Ffmpeg

Severity
5.0MEDIUMNVD
EPSS
0.4%
top 40.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 23
Latest updateMay 17

Description

The avcodec_decode_audio4 function in libavcodec/utils.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 allows remote attackers to trigger memory corruption via vectors related to the channel layout.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDffmpeg/ffmpeg1.0.2+57
debiandebian/ffmpeg

🔴Vulnerability Details

1
GHSA
GHSA-mr5m-24g3-rxxv: The avcodec_decode_audio4 function in libavcodec/utils2022-05-17

📋Vendor Advisories

1
Debian
CVE-2013-0861: ffmpeg - The avcodec_decode_audio4 function in libavcodec/utils.c in FFmpeg before 1.0.4 ...2013