CVE Vulnerabilities

CVE-2013-2495

Published: Mar 09, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The iff_read_header function in iff.c in libavformat in FFmpeg through 1.1.3 does not properly handle data sizes for Interchange File Format (IFF) data during operations involving a CMAP chunk or a video codec, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) or possibly have unspecified other impact via a crafted header.

Affected Software

NameVendorStart VersionEnd Version
FfmpegFfmpeg*1.1.3 (including)
FfmpegFfmpeg0.3 (including)0.3 (including)
FfmpegFfmpeg0.3.1 (including)0.3.1 (including)
FfmpegFfmpeg0.3.2 (including)0.3.2 (including)
FfmpegFfmpeg0.3.3 (including)0.3.3 (including)
FfmpegFfmpeg0.3.4 (including)0.3.4 (including)
FfmpegFfmpeg0.4.0 (including)0.4.0 (including)
FfmpegFfmpeg0.4.2 (including)0.4.2 (including)
FfmpegFfmpeg0.4.3 (including)0.4.3 (including)
FfmpegFfmpeg0.4.4 (including)0.4.4 (including)
FfmpegFfmpeg0.4.5 (including)0.4.5 (including)
FfmpegFfmpeg0.4.6 (including)0.4.6 (including)
FfmpegFfmpeg0.4.7 (including)0.4.7 (including)
FfmpegFfmpeg0.4.8 (including)0.4.8 (including)
FfmpegFfmpeg0.4.9 (including)0.4.9 (including)
FfmpegFfmpeg0.4.9-pre1 (including)0.4.9-pre1 (including)
FfmpegFfmpeg0.5 (including)0.5 (including)
FfmpegFfmpeg0.5.1 (including)0.5.1 (including)
FfmpegFfmpeg0.5.2 (including)0.5.2 (including)
FfmpegFfmpeg0.5.3 (including)0.5.3 (including)
FfmpegFfmpeg0.5.4 (including)0.5.4 (including)
FfmpegFfmpeg0.5.4.5 (including)0.5.4.5 (including)
FfmpegFfmpeg0.5.4.6 (including)0.5.4.6 (including)
FfmpegFfmpeg0.6 (including)0.6 (including)
FfmpegFfmpeg0.6.1 (including)0.6.1 (including)
FfmpegFfmpeg0.6.2 (including)0.6.2 (including)
FfmpegFfmpeg0.6.3 (including)0.6.3 (including)
FfmpegFfmpeg0.7 (including)0.7 (including)
FfmpegFfmpeg0.7.1 (including)0.7.1 (including)
FfmpegFfmpeg0.7.2 (including)0.7.2 (including)
FfmpegFfmpeg0.7.3 (including)0.7.3 (including)
FfmpegFfmpeg0.7.4 (including)0.7.4 (including)
FfmpegFfmpeg0.7.5 (including)0.7.5 (including)
FfmpegFfmpeg0.7.6 (including)0.7.6 (including)
FfmpegFfmpeg0.7.7 (including)0.7.7 (including)
FfmpegFfmpeg0.7.8 (including)0.7.8 (including)
FfmpegFfmpeg0.7.9 (including)0.7.9 (including)
FfmpegFfmpeg0.7.11 (including)0.7.11 (including)
FfmpegFfmpeg0.7.12 (including)0.7.12 (including)
FfmpegFfmpeg0.8.0 (including)0.8.0 (including)
FfmpegFfmpeg0.8.1 (including)0.8.1 (including)
FfmpegFfmpeg0.8.2 (including)0.8.2 (including)
FfmpegFfmpeg0.8.5 (including)0.8.5 (including)
FfmpegFfmpeg0.8.5.3 (including)0.8.5.3 (including)
FfmpegFfmpeg0.8.5.4 (including)0.8.5.4 (including)
FfmpegFfmpeg0.8.6 (including)0.8.6 (including)
FfmpegFfmpeg0.8.7 (including)0.8.7 (including)
FfmpegFfmpeg0.8.8 (including)0.8.8 (including)
FfmpegFfmpeg0.8.10 (including)0.8.10 (including)
FfmpegFfmpeg0.8.11 (including)0.8.11 (including)
FfmpegFfmpeg0.9 (including)0.9 (including)
FfmpegFfmpeg0.9.1 (including)0.9.1 (including)
FfmpegFfmpeg0.10 (including)0.10 (including)
FfmpegFfmpeg0.10.3 (including)0.10.3 (including)
FfmpegFfmpeg0.10.4 (including)0.10.4 (including)
FfmpegFfmpeg0.11 (including)0.11 (including)
FfmpegFfmpeg1.0 (including)1.0 (including)
FfmpegFfmpeg1.1.1 (including)1.1.1 (including)
FfmpegFfmpeg1.1.2 (including)1.1.2 (including)
FfmpegUbuntuhardy*
FfmpegUbuntulucid*
Ffmpeg-extraUbuntulucid*
LibavUbuntuoneiric*
LibavUbuntuprecise*
LibavUbuntuquantal*
LibavUbuntuupstream*
Libav-extraUbuntuoneiric*
Libav-extraUbuntuprecise*
Libav-extraUbuntuquantal*
Libav-extraUbuntuupstream*

References