CVE-2013-2496: Buffer Overflow
The msrledecode8162432 function in msrledec.c in libavcodec in FFmpeg through 1.1.3 does not properly determine certain end pointers, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted Microsoft RLE data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2496?
CVE-2013-2496 has been rated as a moderate severity vulnerability due to its potential for causing denial-of-service attacks.
How do I fix CVE-2013-2496?
To fix CVE-2013-2496, you should upgrade to FFmpeg version 1.1.4 or later, where the vulnerability has been addressed.
What types of impacts can CVE-2013-2496 cause?
CVE-2013-2496 can lead to out-of-bounds array access, resulting in application crashes or denial of service.
Which versions of FFmpeg are affected by CVE-2013-2496?
CVE-2013-2496 affects FFmpeg versions up to 1.1.3 and several earlier versions.
Is CVE-2013-2496 exploitable in a remote context?
Yes, CVE-2013-2496 can be exploited remotely by attackers through crafted input, leading to a denial of service.