CVE-2013-2495: Integer Overflow
The iffreadheader function in iff.c in libavformat in FFmpeg through 1.1.3 does not properly handle data sizes for Interchange File Format (IFF) data during operations involving a CMAP chunk or a video codec, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) or possibly have unspecified other impact via a crafted header.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2495?
CVE-2013-2495 has been classified as a denial of service vulnerability due to integer overflow issues.
How can I fix CVE-2013-2495?
To mitigate CVE-2013-2495, upgrade to FFmpeg version 1.1.4 or later.
What software versions are affected by CVE-2013-2495?
CVE-2013-2495 affects FFmpeg versions up to 1.1.3 and versions from 0.3 to 1.1.3 inclusively.
What kind of attack can CVE-2013-2495 facilitate?
CVE-2013-2495 can allow remote attackers to cause a denial of service through crafted IFF files.
Where can I find more information on CVE-2013-2495?
For detailed information on CVE-2013-2495, refer to the official FFmpeg repository commits.