First published: Mon Jun 10 2013(Updated: )
The cdg_decode_frame function in cdgraphics.c in libavcodec in FFmpeg before 1.2.1 does not validate the presence of non-header data in a buffer, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via crafted CD Graphics Video data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | <=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3674 is classified as a denial of service vulnerability, which can lead to application crashes.
To fix CVE-2013-3674, upgrade to FFmpeg version 1.2.1 or later.
CVE-2013-3674 affects FFmpeg versions prior to 1.2.1.
CVE-2013-3674 allows remote attackers to execute denial of service attacks via crafted CD Graphics Video data.
Yes, CVE-2013-3674 can be exploited remotely, allowing attackers to cause application crashes.