CVE-2013-7020
Mandriva Linux Security Advisory 2014-227
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce certain bit-count and colorspace constraints, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted FFV1 data.
La función read_header function en libavcodec/ffv1dec.c en FFmpeg anterior a v2.1 no aplica correctamente ciertas restricciones en el número de bits y en el espacio de colores, lo que permite a atacantes remotos provocar una denegación de servicio (acceso a array fuera de rango) o posiblemente tener otro impacto no especificado a través de información FFV1 manipulada.
The decode_init function in libavcodec/huffyuv.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted width in huffyuv data with the predictor set to median and the colorspace set to YUV422P, which triggers an out-of-bounds array access. The parse_picture_segment function in libavcodec/pgssubdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted RLE data, which triggers an out-of-bounds array access. The ff_er_frame_end function in libavcodec/error_resilience.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 does not properly verify that a frame is fully initialized, which allows remote attackers to trigger a NULL pointer dereference via crafted picture data. The mm_decode_inter function in mmvideo.c in libavcodec in FFmpeg before 1.2.1 does not validate the relationship between a horizontal coordinate and a width value, which allows remote attackers to cause a denial of service via crafted American Laser Games MM Video data. The cdg_decode_frame function in cdgraphics.c in libavcodec in FFmpeg before 1.2.1 does not validate the presence of non-header data in a buffer, which allows remote attackers to cause a denial of service via crafted CD Graphics Video data. The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce certain bit-count and colorspace constraints, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted FFV1 data. The updated packages have been upgraded to the 0.10.15 version which is not vulnerable to these issues.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-12-08 CVE Reserved
- 2013-12-09 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/61389 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://openwall.com/lists/oss-security/2013/11/26/7 | 2017-01-07 | |
http://openwall.com/lists/oss-security/2013/12/08/3 | 2017-01-07 | |
https://github.com/FFmpeg/FFmpeg/commit/b05cd1ea7e45a836f7f6071a716c38bb30326e0f | 2017-01-07 |
URL | Date | SRC |
---|---|---|
http://ffmpeg.org/security.html | 2017-01-07 | |
http://www.debian.org/security/2014/dsa-3027 | 2017-01-07 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2014:227 | 2017-01-07 | |
https://security.gentoo.org/glsa/201603-06 | 2017-01-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | <= 2.0.1 Search vendor "Ffmpeg" for product "Ffmpeg" and version " <= 2.0.1" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.3 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.3" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.3.1 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.3.1" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.3.2 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.3.2" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.3.3 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.3.3" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.3.4 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.3.4" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.4.0 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.0" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.4.2 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.2" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.4.3 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.3" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.4.4 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.4" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.4.5 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.5" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.4.6 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.6" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.4.7 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.7" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.4.8 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.8" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.4.9 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.4.9" | pre1 |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.5 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.5.1 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5.1" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.5.2 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5.2" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.5.3 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5.3" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.5.4 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5.4" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.5.4.5 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5.4.5" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.5.4.6 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5.4.6" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.5.5 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.5.5" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.6 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.6" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.6.1 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.6.1" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.6.2 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.6.2" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.6.3 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.6.3" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.7 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.7.1 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.1" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.7.2 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.2" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.7.3 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.3" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.7.4 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.4" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.7.5 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.5" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.7.6 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.6" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.7.7 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.7" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.7.8 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.8" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.7.9 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.9" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.7.11 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.11" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.7.12 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.7.12" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.8.0 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.0" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.8.1 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.1" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.8.2 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.2" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.8.5 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.5" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.8.5.3 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.5.3" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.8.5.4 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.5.4" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.8.6 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.6" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.8.7 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.7" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.8.8 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.8" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.8.10 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.10" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.8.11 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.8.11" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.9 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.9" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.9.1 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.9.1" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.10 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.10" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.10.3 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.10.3" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.10.4 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.10.4" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 0.11 Search vendor "Ffmpeg" for product "Ffmpeg" and version "0.11" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 1.0 Search vendor "Ffmpeg" for product "Ffmpeg" and version "1.0" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 1.1.1 Search vendor "Ffmpeg" for product "Ffmpeg" and version "1.1.1" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 1.1.2 Search vendor "Ffmpeg" for product "Ffmpeg" and version "1.1.2" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 1.1.3 Search vendor "Ffmpeg" for product "Ffmpeg" and version "1.1.3" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 1.1.4 Search vendor "Ffmpeg" for product "Ffmpeg" and version "1.1.4" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 1.2 Search vendor "Ffmpeg" for product "Ffmpeg" and version "1.2" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 1.2.1 Search vendor "Ffmpeg" for product "Ffmpeg" and version "1.2.1" | - |
Affected
| ||||||
Ffmpeg Search vendor "Ffmpeg" | Ffmpeg Search vendor "Ffmpeg" for product "Ffmpeg" | 2.0 Search vendor "Ffmpeg" for product "Ffmpeg" and version "2.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 6.0 Search vendor "Debian" for product "Debian Linux" and version "6.0" | - |
Affected
|