Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-3672
HistoryJun 10, 2013 - 12:00 a.m.

CVE-2013-3672

2013-06-1000:00:00
ubuntu.com
ubuntu.com
11

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.004

Percentile

74.0%

The mm_decode_inter function in mmvideo.c in libavcodec in FFmpeg before
1.2.1 does not validate the relationship between a horizontal coordinate
and a width value, which allows remote attackers to cause a denial of
service (out-of-bounds array access and application crash) via crafted
American Laser Games (ALG) MM Video data.

Notes

Author Note
mdeslaur libav and ffmpeg codebases have diverged to the point of not being able to track both using the same CVE numbers. Marking this CVE as not-affected for libav.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS

0.004

Percentile

74.0%