First published: Mon Jun 10 2013(Updated: )
The format_line function in log.c in libavutil in FFmpeg before 1.2.1 uses inapplicable offset data during a certain category calculation, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via crafted data that triggers a log message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | <=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3671 is classified as a medium severity vulnerability due to its potential to cause denial of service.
To fix CVE-2013-3671, upgrade FFmpeg to version 1.2.1 or later.
CVE-2013-3671 can be exploited by remote attackers to cause application crashes through crafted input data.
Versions of FFmpeg prior to 1.2.1 are affected by CVE-2013-3671.
CVE-2013-3671 may lead to denial of service through invalid pointer dereference.