cbcvebase.
CVE-2013-2277
published 2013-02-27

CVE-2013-2277: The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 1.1.3 does not validate the relationship between luma depth and…

PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.99%
78.5th percentile
The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 1.1.3 does not validate the relationship between luma depth and chroma depth, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted H.264 data.

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
debianffmpeg< ffmpeg 7:2.4.1-1 (bookworm)ffmpeg 7:2.4.1-1 (bookworm)
ffmpegffmpeg<= 1.1.2
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg
ffmpegffmpeg

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.