First published: Mon Aug 28 2017(Updated: )
The 'vp3_decode_frame' function in FFmpeg 1.1.4 moves threads check out of header packet type check.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | =1.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0870 has been classified as a moderate severity vulnerability.
To fix CVE-2013-0870, upgrade FFmpeg to version 1.2 or later.
CVE-2013-0870 can potentially allow an attacker to execute arbitrary code through specially crafted media files.
CVE-2013-0870 specifically affects FFmpeg version 1.1.4.
As of the latest available information, there have been no public reports of active exploitation of CVE-2013-0870.