Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-7020
HistoryDec 09, 2013 - 12:00 a.m.

CVE-2013-7020

2013-12-0900:00:00
ubuntu.com
ubuntu.com
13

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.021

Percentile

89.1%

The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does
not properly enforce certain bit-count and colorspace constraints, which
allows remote attackers to cause a denial of service (out-of-bounds array
access) or possibly have unspecified other impact via crafted FFV1 data.

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.021

Percentile

89.1%