CVE-2013-0866: Buffer Overflow
The aacdecodeinit function in libavcodec/aacdec.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large number of channels in an AAC file, which triggers an out-of-bounds array access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0866?
CVE-2013-0866 is classified as a high severity vulnerability due to the potential for remote attackers to cause out-of-bounds array access.
How do I fix CVE-2013-0866?
To fix CVE-2013-0866, upgrade FFmpeg to version 1.0.4 or later, or 1.1.2 or later.
Which versions of FFmpeg are affected by CVE-2013-0866?
CVE-2013-0866 affects FFmpeg versions before 1.0.4 and 1.1.x versions before 1.1.2.
What impact can CVE-2013-0866 have on the system?
CVE-2013-0866 can lead to undefined behavior in the application running FFmpeg, potentially allowing remote code execution.
Is CVE-2013-0866 a common vulnerability?
CVE-2013-0866 has been noted in multiple versions of FFmpeg, making it a significant concern for users of outdated software.