CVE-2013-0868: Buffer Overflow
libavcodec/huffyuvdec.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted Huffyuv data, related to an out-of-bounds write and (1) unchecked return codes from the initvlc function and (2) "len==0 cases."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0868?
CVE-2013-0868 has a medium severity rating due to its potential for permitting out-of-bounds write vulnerabilities.
How do I fix CVE-2013-0868?
To fix CVE-2013-0868, update to FFmpeg version 1.1.2 or later, as it includes the necessary patches.
What kind of attack does CVE-2013-0868 facilitate?
CVE-2013-0868 allows remote attackers to exploit crafted Huffyuv data to cause an unspecified impact.
Which versions of FFmpeg are affected by CVE-2013-0868?
FFmpeg versions prior to 1.1.2, including all versions from 0.3 to 1.1.1, are vulnerable to CVE-2013-0868.
Is my system at risk with CVE-2013-0868?
If you are using an affected version of FFmpeg, your system is at risk of exploitation through this vulnerability.