CVE-2013-0875Ffmpeg vulnerability

CWE-1895 documents5 sources
Severity
9.3CRITICALNVD
EPSS
0.7%
top 27.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 23
Latest updateMay 17

Description

The ff_add_png_paeth_prediction function in libavcodec/pngdec.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via a crafted PNG image, related to an out-of-bounds array access.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDffmpeg/ffmpeg1.1.2+56
debiandebian/ffmpeg

🔴Vulnerability Details

1
GHSA
GHSA-9f2c-hm4f-5cv7: The ff_add_png_paeth_prediction function in libavcodec/pngdec2022-05-17

📋Vendor Advisories

2
Red Hat
qffmpeg: out-of-bounds array access in libavcodec/pngdec.c2013-02-13
Debian
CVE-2013-0875: ffmpeg - The ff_add_png_paeth_prediction function in libavcodec/pngdec.c in FFmpeg before...2013

💬Community

1
Bugzilla
CVE-2013-0875 qffmpeg: out-of-bounds array access in libavcodec/pngdec.c2013-11-26