CVE-2013-0876: Integer Overflow
Multiple integer overflows in the (1) oldcodec37 and (2) oldcodec47 functions in libavcodec/sanm.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via crafted LucasArts Smush data, which triggers an out-of-bounds array access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0876?
CVE-2013-0876 has a severity rating that indicates it can be exploited by remote attackers to affect the application's stability and behavior.
How do I fix CVE-2013-0876?
To fix CVE-2013-0876, upgrade FFmpeg to version 1.1.3 or later.
What components of FFmpeg are affected by CVE-2013-0876?
CVE-2013-0876 affects the old_codec37 and old_codec47 functions in the libavcodec/sanm.c file.
Can CVE-2013-0876 be exploited remotely?
Yes, CVE-2013-0876 can be exploited remotely via crafted LucasArts Smush data.
Which versions of FFmpeg are vulnerable to CVE-2013-0876?
Versions of FFmpeg prior to 1.1.3, as well as specific earlier versions like 0.3 to 0.10.x, are vulnerable to CVE-2013-0876.