CVE Vulnerabilities

CVE-2013-0870

Published: Aug 28, 2017 | Modified: Apr 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io minimus.io echohq.com

The vp3_decode_frame function in FFmpeg 1.1.4 moves threads check out of header packet type check.

Affected Software

Name Vendor Start Version End Version
Ffmpeg Ffmpeg 1.1.4 (including) 1.1.4 (including)
Ffmpeg Ubuntu lucid *
Ffmpeg-extra Ubuntu lucid *

References