CVE-2013-0853: Critical severity ffmpeg vulnerability
The wavpackdecodeframe function in libavcodec/wavpack.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted WavPack data, which triggers an out-of-bounds array access, possibly due to an off-by-one error.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0853?
CVE-2013-0853 is classified as a moderate severity vulnerability due to the potential for out-of-bounds array access leading to unspecified impacts.
How do I fix CVE-2013-0853?
To fix CVE-2013-0853, users should upgrade to FFmpeg version 1.1 or later.
What causes CVE-2013-0853?
CVE-2013-0853 is caused by improper handling of crafted WavPack data, resulting in an out-of-bounds array access.
Which versions of FFmpeg are affected by CVE-2013-0853?
CVE-2013-0853 affects FFmpeg versions prior to 1.1, as well as specific earlier versions listed in the vulnerability documentation.
Can CVE-2013-0853 be exploited remotely?
Yes, CVE-2013-0853 can potentially be exploited remotely through the use of specially crafted WavPack files.