SB2013100406 - Multiple vulnerabilities in FFmpeg



SB2013100406 - Multiple vulnerabilities in FFmpeg

Published: October 4, 2013 Updated: June 8, 2025

Security Bulletin ID SB2013100406
Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2013-3675)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The process_frame_obj function in sanm.c in libavcodec in FFmpeg before 1.2.1 does not validate width and height values, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) via crafted LucasArts Smush video data.


2) Input validation error (CVE-ID: CVE-2013-3674)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The cdg_decode_frame function in cdgraphics.c in libavcodec in FFmpeg before 1.2.1 does not validate the presence of non-header data in a buffer, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via crafted CD Graphics Video data.


3) Buffer overflow (CVE-ID: CVE-2013-3673)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The gif_decode_frame function in gifdec.c in libavcodec in FFmpeg before 1.2.1 does not properly manage the disposal methods of frames, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via crafted GIF data.


4) Input validation error (CVE-ID: CVE-2013-3672)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The mm_decode_inter function in mmvideo.c in libavcodec in FFmpeg before 1.2.1 does not validate the relationship between a horizontal coordinate and a width value, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via crafted American Laser Games (ALG) MM Video data.


5) Input validation error (CVE-ID: CVE-2013-3671)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The format_line function in log.c in libavutil in FFmpeg before 1.2.1 uses inapplicable offset data during a certain category calculation, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via crafted data that triggers a log message.


Remediation

Install update from vendor's website.