First published: Mon Jun 10 2013(Updated: )
The process_frame_obj function in sanm.c in libavcodec in FFmpeg before 1.2.1 does not validate width and height values, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) via crafted LucasArts Smush video data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | <=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-3675 is classified as moderate due to its potential to cause denial of service.
To fix CVE-2013-3675, upgrade to FFmpeg version 1.2.1 or later.
CVE-2013-3675 is an integer overflow vulnerability that may lead to out-of-bounds access.
CVE-2013-3675 affects FFmpeg versions prior to 1.2.1.
Yes, CVE-2013-3675 can be exploited remotely through crafted LucasArts Smush video data.