CVE-2013-3671Ffmpeg vulnerability

CWE-1893 documents3 sources
Severity
4.3MEDIUMNVD
EPSS
0.5%
top 34.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 10
Latest updateMay 17

Description

The format_line function in log.c in libavutil in FFmpeg before 1.2.1 uses inapplicable offset data during a certain category calculation, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via crafted data that triggers a log message.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDffmpeg/ffmpeg1.2
debiandebian/ffmpeg

🔴Vulnerability Details

1
GHSA
GHSA-5m89-g37f-fx5p: The format_line function in log2022-05-17

📋Vendor Advisories

1
Debian
CVE-2013-3671: ffmpeg - The format_line function in log.c in libavutil in FFmpeg before 1.2.1 uses inapp...2013