Release date:
Updated on:
Affected Systems:
FFmpeg 1.2.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 60476
CVE (CAN) ID: CVE-2013-3670
FFmpeg is a free software that allows you to perform video, transfer, and stream functions in multiple formats of audio and video.
In FFmpeg 1.2.1, The rle_unpack function of vmdav. c In libavcodec does not correctly use the bytestream2 API, and a denial of service vulnerability exists. Attackers can exploit this vulnerability to cause the affected database to crash through specially crafted RLE data.
<* Source: Mateusz & quot; j00ru & quot; Jurczyk
Gynvael Coldwind
Link: http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2013-3670
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
FFmpeg
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://ffmpeg.org/security.html