CVE-2013-0870: Critical severity ffmpeg vulnerability
Published Aug 28, 2017
·Updated
The 'vp3decodeframe' function in FFmpeg 1.1.4 moves threads check out of header packet type check.
Affected Software
1 affected component
FFmpeg FFmpeg=1.1.4
Remediation
Patch Available
Event History
Aug 28, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0870?
CVE-2013-0870 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2013-0870?
To fix CVE-2013-0870, upgrade FFmpeg to version 1.2 or later.
3
What is the impact of CVE-2013-0870?
CVE-2013-0870 can potentially allow an attacker to execute arbitrary code through specially crafted media files.
4
Which versions of FFmpeg are affected by CVE-2013-0870?
CVE-2013-0870 specifically affects FFmpeg version 1.1.4.
5
Is CVE-2013-0870 being actively exploited?
As of the latest available information, there have been no public reports of active exploitation of CVE-2013-0870.