// For flags

CVE-2013-0860

Debian Security Advisory 3003-1

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The ff_er_frame_end function in libavcodec/error_resilience.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 does not properly verify that a frame is fully initialized, which allows remote attackers to trigger a NULL pointer dereference via crafted picture data.

La función ff_er_frame_end de ibavcodec/error_resilience.c en FFmpeg anterior a la versión 1.0.4 y 1.1.x anterior a 1.1.1 no verifica adecuadamente que un frame está completamente inicializado, lo que permite a atacantes remotos provocar una referencia a puntero nulo a través de datos de imagen manipulados.

The decode_init function in libavcodec/huffyuv.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted width in huffyuv data with the predictor set to median and the colorspace set to YUV422P, which triggers an out-of-bounds array access. The parse_picture_segment function in libavcodec/pgssubdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted RLE data, which triggers an out-of-bounds array access. The ff_er_frame_end function in libavcodec/error_resilience.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 does not properly verify that a frame is fully initialized, which allows remote attackers to trigger a NULL pointer dereference via crafted picture data. The mm_decode_inter function in mmvideo.c in libavcodec in FFmpeg before 1.2.1 does not validate the relationship between a horizontal coordinate and a width value, which allows remote attackers to cause a denial of service via crafted American Laser Games MM Video data. The cdg_decode_frame function in cdgraphics.c in libavcodec in FFmpeg before 1.2.1 does not validate the presence of non-header data in a buffer, which allows remote attackers to cause a denial of service via crafted CD Graphics Video data. The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce certain bit-count and colorspace constraints, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted FFV1 data. The updated packages have been upgraded to the 0.10.15 version which is not vulnerable to these issues.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-01-07 CVE Reserved
  • 2013-11-23 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
<= 1.0.3
Search vendor "Ffmpeg" for product "Ffmpeg" and version " <= 1.0.3"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.3
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.3"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.3.1
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.3.1"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.3.2
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.3.2"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.3.3
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.3.3"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.3.4
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.3.4"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.4.0
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.0"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.4.2
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.2"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.4.3
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.3"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.4.4
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.4"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.4.5
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.5"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.4.6
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.6"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.4.7
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.7"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.4.8
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.8"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.4.9
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.9"
pre1
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.5
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.5.1
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5.1"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.5.2
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5.2"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.5.3
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5.3"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.5.4
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5.4"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.5.4.5
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5.4.5"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.5.4.6
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5.4.6"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.6
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.6"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.6.1
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.6.1"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.6.2
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.6.2"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.6.3
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.6.3"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.7
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.7.1
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.1"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.7.2
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.2"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.7.3
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.3"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.7.4
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.4"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.7.5
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.5"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.7.6
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.6"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.7.7
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.7"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.7.8
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.8"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.7.9
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.9"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.7.11
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.11"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.7.12
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.12"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.8.0
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.0"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.8.1
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.1"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.8.2
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.2"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.8.5
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.5"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.8.5.3
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.5.3"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.8.5.4
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.5.4"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.8.6
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.6"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.8.7
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.7"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.8.8
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.8"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.8.10
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.10"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.8.11
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.11"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.9
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.9"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.9.1
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.9.1"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.10
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.10"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.10.3
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.10.3"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.10.4
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.10.4"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
0.11
Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.11"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
1.0
Search vendor "Ffmpeg" for product "Ffmpeg" and version "1.0"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
1.0.1
Search vendor "Ffmpeg" for product "Ffmpeg" and version "1.0.1"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
1.0.2
Search vendor "Ffmpeg" for product "Ffmpeg" and version "1.0.2"
-
Affected
Ffmpeg
Search vendor "Ffmpeg"
Ffmpeg
Search vendor "Ffmpeg" for product "Ffmpeg"
1.1
Search vendor "Ffmpeg" for product "Ffmpeg" and version "1.1"
-
Affected