CVE-2013-0860: Input Validation
The fferframeend function in libavcodec/errorresilience.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 does not properly verify that a frame is fully initialized, which allows remote attackers to trigger a NULL pointer dereference via crafted picture data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0860?
CVE-2013-0860 has a severity rating that indicates it could lead to a NULL pointer dereference, allowing remote attackers to exploit the vulnerability.
How do I fix CVE-2013-0860?
To fix CVE-2013-0860, upgrade to FFmpeg version 1.0.4 or later, or 1.1.1 or later.
Which versions are affected by CVE-2013-0860?
CVE-2013-0860 affects FFmpeg versions prior to 1.0.4 and all versions of 1.1.x before 1.1.1.
What type of vulnerability is CVE-2013-0860?
CVE-2013-0860 is classified as a denial of service vulnerability due to a NULL pointer dereference.
Can CVE-2013-0860 be exploited remotely?
Yes, CVE-2013-0860 can be exploited remotely through crafted picture data.