CVE-2013-0856: Input Validation
The lpcprediction function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Apple Lossless Audio Codec (ALAC) data, related to a large nbsamples value.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0856?
CVE-2013-0856 is considered to have an unspecified severity that allows potential remote attackers to exploit the vulnerability through crafted ALAC data.
How do I fix CVE-2013-0856?
To fix CVE-2013-0856, upgrade to a version of FFmpeg that is 1.1 or higher, as it includes patches for the vulnerability.
What versions of FFmpeg are affected by CVE-2013-0856?
CVE-2013-0856 affects all versions of FFmpeg before 1.1, including specific older versions down to 0.3.
Can CVE-2013-0856 be exploited remotely?
Yes, CVE-2013-0856 can be exploited remotely through the manipulation of crafted Apple Lossless Audio Codec data.
What impact does CVE-2013-0856 have on systems?
The impact of CVE-2013-0856 can be undefined, but it poses risks related to processing malicious ALAC files that may affect software stability.