CVE-2013-0849: Input Validation
The roqdecodeinit function in libavcodec/roqvideodec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted (1) width or (2) height dimension that is not a multiple of sixteen in id RoQ video data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0849?
CVE-2013-0849 is rated as a potential risk as it allows remote attackers to exploit crafted width or height dimensions in id RoQ video data.
How do I fix CVE-2013-0849?
To fix CVE-2013-0849, upgrade to FFmpeg version 1.1 or later, which addresses the vulnerability.
What software is affected by CVE-2013-0849?
CVE-2013-0849 affects various versions of FFmpeg prior to version 1.1.
What type of attack does CVE-2013-0849 facilitate?
CVE-2013-0849 facilitates potential remote code execution attacks through specially crafted video files.
Can I mitigate CVE-2013-0849 without upgrading?
Mitigating CVE-2013-0849 without an upgrade is difficult; it's strongly recommended to update to the latest version of FFmpeg.