CVE-2013-0848: Buffer Overflow
The decodeinit function in libavcodec/huffyuv.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted width in huffyuv data with the predictor set to median and the colorspace set to YUV422P, which triggers an out-of-bounds array access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0848?
CVE-2013-0848 has a severity rating that indicates it allows remote attackers to cause an out-of-bounds array access.
How do I fix CVE-2013-0848?
To fix CVE-2013-0848, upgrade FFmpeg to version 1.1 or later, which addresses the vulnerability.
Which versions of FFmpeg are affected by CVE-2013-0848?
CVE-2013-0848 affects FFmpeg versions prior to 1.1, including specific versions from 0.3 to 0.10.4.
What type of vulnerability is CVE-2013-0848?
CVE-2013-0848 is an out-of-bounds read vulnerability that can be exploited by crafting specific huffyuv data.
Can CVE-2013-0848 be exploited remotely?
Yes, CVE-2013-0848 can be exploited remotely by sending a crafted width in huffyuv data.