CVE-2013-4264Improper Restriction of Operations within the Bounds of a Memory Buffer in Ffmpeg

Severity
4.3MEDIUMNVD
EPSS
0.8%
top 25.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 23
Latest updateMay 17

Description

The kempf_decode_tile function in libavcodec/g2meet.c in FFmpeg before 2.0.1 allows remote attackers to cause a denial of service (out-of-bounds heap write) via a G2M4 encoded file.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDffmpeg/ffmpeg2.0+60
debiandebian/ffmpeg

Patches

🔴Vulnerability Details

1
GHSA
GHSA-44mw-xh3m-998r: The kempf_decode_tile function in libavcodec/g2meet2022-05-17

📋Vendor Advisories

1
Debian
CVE-2013-4264: ffmpeg - The kempf_decode_tile function in libavcodec/g2meet.c in FFmpeg before 2.0.1 all...2013