← Back

CVE-2013-0860

nvd nist
Published: Nov 23, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The ff_er_frame_end function in libavcodec/error_resilience.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 does not properly verify that a frame is fully initialized, which allows remote attackers to trigger a NULL pointer dereference via crafted picture data.

Affected (59)

Products: Ffmpeg: Ffmpeg
1 product
Ffmpeg
Configuration A
59 vulnerable
Vulnerable SoftwareAffected Versions
Ffmpeg
Up to 1.0.3
Version 0.10.3
Version 0.10.4
Version 0.10
Version 0.11
Version 0.3.1
Version 0.3.2
Version 0.3.3
Version 0.3.4
Version 0.3
Version 0.4.0
Version 0.4.2
Version 0.4.3
Version 0.4.4
Version 0.4.5
Version 0.4.6
Version 0.4.7
Version 0.4.8
Version 0.4.9 pre1
Version 0.5.1
Version 0.5.2
Version 0.5.3
Version 0.5.4.5
Version 0.5.4.6
Version 0.5.4
Version 0.5
Version 0.6.1
Version 0.6.2
Version 0.6.3
Version 0.6
Version 0.7.11
Version 0.7.12
Version 0.7.1
Version 0.7.2
Version 0.7.3
Version 0.7.4
Version 0.7.5
Version 0.7.6
Version 0.7.7
Version 0.7.8
Version 0.7.9
Version 0.7
Version 0.8.0
Version 0.8.10
Version 0.8.11
Version 0.8.1
Version 0.8.2
Version 0.8.5.3
Version 0.8.5.4
Version 0.8.5
Version 0.8.6
Version 0.8.7
Version 0.8.8
Version 0.9.1
Version 0.9
Version 1.0.1
Version 1.0.2
Version 1.0
Version 1.1

Timeline

No history available yet.