FFmpeg Multiple Vulnerabilities
Last Update Date:
5 Mar 2013 16:01
Release Date:
5 Mar 2013
4956
Views
RISK: Medium Risk
TYPE: Clients - Audio & Video
Multiple vulnerabilities have been identified in FFmpeg, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.
- An error within the "ff_h264_decode_seq_parameter_set()" function (libavcodec/h264_ps.c) when decoding certain parameter set can be exploited to cause an out of array access violation.
- An error within the "attribute_align_arg avcodec_decode_audio4()" function (libavcodec/utils.c) can be exploited to cause an out of array access violation.
- An error within the "swr_init()" function (libswresample/swresample.c) can be exploited to cause an out of array access violation.
- An error within the "read_header()" function (libavcodec/shorten.c) can be exploited to free invalid addresses.
- An error within the "doubles2str()" and "shorts2str()" functions (libavcodec/tiff.c) can be exploited to cause an out of array access violation.
- An error within the "ff_add_png_paeth_prediction()" function (libavcodec/pngdec.c) can be exploited to cause an out of array access violation.
- An integer overflow error within the "old_codec37()" function (libavcodec/sanm.c) can be exploited to corrupt memory.
- An error within the "old_codec37()" function (libavcodec/sanm.c) can be exploited to cause an out of array access violation.
- An error within the "advance_line()" function (libavcodec/targa.c) can be exploited to cause an out of array access violation.
Impact
- Denial of Service
System / Technologies affected
- FFmpeg versions prior to 1.1.3.
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 1.1.3.
Vulnerability Identifier
- CVE-2013-0872
- CVE-2013-0873
- CVE-2013-0874
- CVE-2013-0875
- CVE-2013-0876
- CVE-2013-0877
- CVE-2013-0878
- CVE-2013-2276
- CVE-2013-2277
Source
Related Link
Share with