CVE-2013-0862: Integer Overflow
Multiple integer overflows in the processframeobj function in libavcodec/sanm.c in FFmpeg before 1.1.2 allow remote attackers to have an unspecified impact via crafted image dimensions in LucasArts Smush video data, which triggers an out-of-bounds array access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0862?
CVE-2013-0862 has a severity rating that indicates it can lead to remote code execution due to integer overflows.
How do I fix CVE-2013-0862?
To fix CVE-2013-0862, upgrade FFmpeg to version 1.1.2 or later.
Which versions of FFmpeg are affected by CVE-2013-0862?
CVE-2013-0862 affects all FFmpeg versions prior to 1.1.2, including versions 0.3.0 through 1.1.1.
What impact can CVE-2013-0862 have on my system?
CVE-2013-0862 can cause an unspecified impact, allowing remote attackers to exploit the vulnerability through crafted media files.
How can I determine if my FFmpeg version is vulnerable to CVE-2013-0862?
Check your FFmpeg version against the official release notes to confirm if it is prior to version 1.1.2, which is vulnerable.