Release date:
Updated on:
Affected Systems:
FFmpeg <1.1.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58237
CVE (CAN) ID: CVE-2013-2276
FFmpeg is a free software that allows you to perform video, transfer, and stream functions in multiple formats of audio and video.
The avcodec_decode_audio4 function of utils. c In libavcodec earlier than FFmpeg 1.1.3 does not verify the encoding status before performing some skipping operations. This allows remote attackers to cause denial of service (out-of-bounds array access and application crash ).
<* Source: Mateusz "j00ru" Jurczyk
Gynvael Coldwind
Link: http://git.videolan.org /? P = ffmpeg. git; a = commit; h = 8a6449167a6da8cb747cfe3502ae86ffaac2ed48
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
FFmpeg
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://ffmpeg.org/security.html