#VU42334 Buffer overflow in FFmpeg - CVE-2013-0877
Published: November 23, 2013 / Updated: August 10, 2020
FFmpeg
ffmpeg.sourceforge.net
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The old_codec37 function in libavcodec/sanm.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via crafted LucasArts Smush data that has a large size when decoded, related to an out-of-bounds array access.