Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-0864
HistoryNov 23, 2013 - 12:00 a.m.

CVE-2013-0864

2013-11-2300:00:00
ubuntu.com
ubuntu.com
7

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.004 Low

EPSS

Percentile

75.2%

The gif_copy_img_rect function in libavcodec/gifdec.c in FFmpeg before
1.1.2 performs an incorrect calculation for an “end pointer,” which allows
remote attackers to have an unspecified impact via crafted GIF data that
triggers an out-of-bounds array access.

Notes

Author Note
mdeslaur libav and ffmpeg codebases have diverged to the point of not being able to track both using the same CVE numbers. Marking this CVE as not-affected for libav.

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.004 Low

EPSS

Percentile

75.2%