← Back

CVE-2013-0894

nvd nist
Published: Feb 23, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (divide-by-zero error or out-of-bounds array access) or possibly have unspecified other impact via vectors involving a zero value for a bark map size.

Affected (7)

Products: Google: Chrome · Ffmpeg: Ffmpeg · Opensuse: Opensuse · +1 more
Show all products
1 product
Chrome
1 product
Ffmpeg
1 product
Opensuse
1 product
Ubuntu Linux
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 25.0.1364.99
Running on/withPlatform Versions
Apple
Macos
All versions
Configuration B
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 25.0.1364.97
Running on/withPlatform Versions
Linux
Linux Kernel
All versions
Microsoft
Windows
All versions
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.1.3
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 12.1
Version 12.2
Configuration E
2 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 12.10

Timeline

No history available yet.