CVE-2013-0868Improper Restriction of Operations within the Bounds of a Memory Buffer in Ffmpeg

Severity
9.3CRITICALNVD
NVD5.5
EPSS
0.9%
top 24.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 23
Latest updateMay 24

Description

libavcodec/huffyuvdec.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted Huffyuv data, related to an out-of-bounds write and (1) unchecked return codes from the init_vlc function and (2) "len==0 cases."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

debiandebian/ffmpeg< ffmpeg 7:4.4.1-1 (bookworm)+1
Debianffmpeg/ffmpeg< 7:2.4.1-1+7
NVDffmpeg/ffmpeg1.1.1+56

Also affects: Debian Linux 10.0, 11.0, 9.0

🔴Vulnerability Details

4
GHSA
GHSA-97g5-wwgm-hp9g: libavcodec/dnxhddec2022-05-24
GHSA
GHSA-j4v2-7rrj-34px: libavcodec/huffyuvdec2022-05-17
OSV
CVE-2021-38114: libavcodec/dnxhddec2021-08-04
OSV
CVE-2013-0868: libavcodec/huffyuvdec2013-11-23

📋Vendor Advisories

2
Debian
CVE-2021-38114: ffmpeg - libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of the init_...2021
Debian
CVE-2013-0868: ffmpeg - libavcodec/huffyuvdec.c in FFmpeg before 1.1.2 allows remote attackers to have a...2013