CVE-2013-2277: High severity ffmpeg vulnerability
The ffh264decodeseqparameterset function in h264ps.c in libavcodec in FFmpeg before 1.1.3 does not validate the relationship between luma depth and chroma depth, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted H.264 data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2277?
The severity of CVE-2013-2277 is categorized as high due to its potential to cause denial of service.
How do I fix CVE-2013-2277?
To fix CVE-2013-2277, upgrade to FFmpeg version 1.1.3 or later.
What type of vulnerability is CVE-2013-2277?
CVE-2013-2277 is a vulnerability related to improper validation of video parameters in FFmpeg.
Which versions of FFmpeg are affected by CVE-2013-2277?
FFmpeg versions prior to 1.1.3, as well as versions 0.3 to 1.1.2, are affected by CVE-2013-2277.
What are the potential impacts of CVE-2013-2277?
The potential impacts of CVE-2013-2277 include application crashes and denial of service due to out-of-bounds array access.