Input validation error in FFmpeg - CVE-2013-0864
Published: November 23, 2013 / Updated: August 10, 2020
FFmpeg
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The gif_copy_img_rect function in libavcodec/gifdec.c in FFmpeg before 1.1.2 performs an incorrect calculation for an "end pointer," which allows remote attackers to have an unspecified impact via crafted GIF data that triggers an out-of-bounds array access.