CVE-2013-7010
published 2013-12-09CVE-2013-7010: Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 allow remote attackers to cause a denial of service (out-of-bounds array…
PriorityP426medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.67%
84.2th percentile
Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted data.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 2.0.1 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
qffmpeg: integer overflow and out of array accesses in libavcodec/dsputil.c
vendor_redhat·2013-08-30·CVSS 6.8
CVE-2013-7010 [MEDIUM] CWE-190 qffmpeg: integer overflow and out of array accesses in libavcodec/dsputil.c
qffmpeg: integer overflow and out of array accesses in libavcodec/dsputil.c
Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted data.
Statement: The Red Hat Security Response Team has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: qffmpeg (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2013-7010: ffmpeg - Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 ...
vendor_debian·2013·CVSS 6.8
CVE-2013-7010 [MEDIUM] CVE-2013-7010: ffmpeg - Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 ...
Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted data.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
GHSA
GHSA-hjq3-qcx4-mc3m: Multiple integer signedness errors in libavcodec/dsputil
ghsa_unreviewed·2022-05-17
CVE-2013-7010 [MEDIUM] GHSA-hjq3-qcx4-mc3m: Multiple integer signedness errors in libavcodec/dsputil
Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted data.
OSV
CVE-2013-7010: Multiple integer signedness errors in libavcodec/dsputil
osv·2013-12-09·CVSS 6.8
CVE-2013-7010 [MEDIUM] CVE-2013-7010: Multiple integer signedness errors in libavcodec/dsputil
Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted data.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-7010 qffmpeg: integer overflow and out of array accesses in libavcodec/dsputil.c
bugzilla·2013-11-27·CVSS 6.8
CVE-2013-7010 [MEDIUM] CVE-2013-7010 qffmpeg: integer overflow and out of array accesses in libavcodec/dsputil.c
CVE-2013-7010 qffmpeg: integer overflow and out of array accesses in libavcodec/dsputil.c
The libavcodec/dsputil.c in FFmpeg was found to have a integer overflow and out of array accesses vulnerabilities.
The issue is fixed by fixing the signedness in sizeof() comparisons.
References:
http://seclists.org/oss-sec/2013/q4/341
Commit:
https://github.com/FFmpeg/FFmpeg/commit/454a11a1c9c686c78aa97954306fb63453299760
Discussion:
Statement:
The Red Hat Security Response Team has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
arXiv
Game Rewards Vulnerabilities: Software Vulnerability Detection with Zero-Sum Game and Prototype Learning
arxiv_fulltext·2024-01-16
Game Rewards Vulnerabilities: Software Vulnerability Detection with Zero-Sum Game and Prototype Learning
Game Rewards Vulnerabilities: Software Vulnerability Detection with Zero-Sum Game and Prototype Learning
Xin-Cheng Wen2,
Cuiyun Gao1* corresponding author.2,
Xinchen Wang2,
Ruiqi Wang2,
Tao Zhang4,
and Qing Liao2
2Harbin Institute of Technology, Shenzhen, China
4 Macau University of Science and Technology, Macau, China
[email protected], [email protected], \200111115, 200111606\@stu.hit.edu.cn, [email protected], [email protected]
## Abstract
Recent years have witnessed a growing focus on automated software vulnerability detection. Notably, deep learning (DL)-based methods, which employ source code for the implicit acquisition of vulnerability patterns, have demonstrated superior performance compared to other approaches.
However, the DL-based approaches are still hard to c
http://ffmpeg.org/security.htmlhttp://git.libav.org/?p=libav.git%3Ba=blob%3Bf=Changelog%3Bhb=refs/tags/v9.11http://openwall.com/lists/oss-security/2013/11/26/7http://openwall.com/lists/oss-security/2013/12/08/3http://www.debian.org/security/2014/dsa-2855https://github.com/FFmpeg/FFmpeg/commit/454a11a1c9c686c78aa97954306fb63453299760https://security.gentoo.org/glsa/201603-06http://ffmpeg.org/security.htmlhttp://git.libav.org/?p=libav.git%3Ba=blob%3Bf=Changelog%3Bhb=refs/tags/v9.11http://openwall.com/lists/oss-security/2013/11/26/7http://openwall.com/lists/oss-security/2013/12/08/3http://www.debian.org/security/2014/dsa-2855https://github.com/FFmpeg/FFmpeg/commit/454a11a1c9c686c78aa97954306fb63453299760https://security.gentoo.org/glsa/201603-06
2013-12-09
Published