CVE-2013-7023: Buffer Overflow
The ffcombineframe function in libavcodec/parser.c in FFmpeg before 2.1 does not properly handle certain memory-allocation errors, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted data.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7023?
CVE-2013-7023 has a moderate severity level, potentially leading to denial of service due to out-of-bounds array access.
How do I fix CVE-2013-7023?
To fix CVE-2013-7023, upgrade to a version of FFmpeg that is 2.1 or later.
Which versions of FFmpeg are affected by CVE-2013-7023?
FFmpeg versions before 2.1, including 0.3 through 2.0.1, are affected by CVE-2013-7023.
What types of exploits are possible with CVE-2013-7023?
CVE-2013-7023 allows remote attackers to exploit memory-allocation errors to cause denial of service or potentially other unspecified impacts.
Is there a workaround for CVE-2013-7023 if I cannot update?
There is no known workaround for CVE-2013-7023, so updating to a secure version is essential.