CVE-2013-0865: Buffer Overflow
The vqadecodechunk function in libavcodec/vqavideo.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large (1) cbp0 or (2) cbpz chunk in Westwood Studios VQA Video file, which triggers an out-of-bounds write.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0865?
CVE-2013-0865 has a medium severity level due to the potential for remote code execution via crafted video files.
How do I fix CVE-2013-0865?
To fix CVE-2013-0865, upgrade FFmpeg to version 1.0.4 or later, or 1.1.2 or later.
What software is affected by CVE-2013-0865?
CVE-2013-0865 affects multiple versions of FFmpeg, including versions prior to 1.0.4 and 1.1.x before 1.1.2.
Can CVE-2013-0865 be exploited remotely?
Yes, CVE-2013-0865 can be exploited by remote attackers through specially crafted Westwood Studios VQA Video files.
What are the consequences of exploiting CVE-2013-0865?
Exploitation of CVE-2013-0865 may lead to an out-of-bounds write, resulting in potential data corruption or arbitrary code execution.