CVE-2013-0873
published 2013-11-23CVE-2013-0873: The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid channel count…
PriorityP341critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.84%
85.2th percentile
The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid channel count, related to "freeing invalid addresses."
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 1.1.2 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
qffmpeg: Invalid free in libavcodec/shorten.c due to invalid channel count
vendor_redhat·2013-02-13·CVSS 10.0
CVE-2013-0873 [CRITICAL] qffmpeg: Invalid free in libavcodec/shorten.c due to invalid channel count
qffmpeg: Invalid free in libavcodec/shorten.c due to invalid channel count
The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid channel count, related to "freeing invalid addresses."
Statement: The Red Hat Security Response Team has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: qffmpeg (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2013-0873: ffmpeg - The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows r...
vendor_debian·2013·CVSS 10.0
CVE-2013-0873 [CRITICAL] CVE-2013-0873: ffmpeg - The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows r...
The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid channel count, related to "freeing invalid addresses."
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-rh57-95h4-wx3g: The read_header function in libavcodec/shorten
ghsa_unreviewed·2022-05-17
CVE-2013-0873 [HIGH] CWE-20 GHSA-rh57-95h4-wx3g: The read_header function in libavcodec/shorten
The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid channel count, related to "freeing invalid addresses."
OSV
CVE-2013-0873: The read_header function in libavcodec/shorten
osv·2013-11-23·CVSS 10.0
CVE-2013-0873 [CRITICAL] CVE-2013-0873: The read_header function in libavcodec/shorten
The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid channel count, related to "freeing invalid addresses."
No detection rules found.
No public exploits indexed.
http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=4f1279154ee9baf2078241bf5619774970d18b25http://www.ffmpeg.org/security.htmlhttps://security.gentoo.org/glsa/201603-06http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=4f1279154ee9baf2078241bf5619774970d18b25http://www.ffmpeg.org/security.htmlhttps://security.gentoo.org/glsa/201603-06
2013-11-23
Published