CVE-2013-7013: Medium severity FFmpeg FFmpeg vulnerability
The g2minitbuffers function in libavcodec/g2meet.c in FFmpeg before 2.1 uses an incorrect ordering of arithmetic operations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Go2Webinar data.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7013?
CVE-2013-7013 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2013-7013?
To mitigate CVE-2013-7013, upgrade to FFmpeg version 2.1 or later.
What causes CVE-2013-7013?
CVE-2013-7013 is caused by an incorrect ordering of arithmetic operations in the g2m_init_buffers function, leading to out-of-bounds array access.
Can CVE-2013-7013 be exploited remotely?
Yes, CVE-2013-7013 can be exploited by remote attackers through crafted Go2Webinar data.
Which versions of FFmpeg are affected by CVE-2013-7013?
CVE-2013-7013 affects all FFmpeg versions prior to 2.1, including versions up to 2.0.1.