← Back

CVE-2013-3675

nvd nist
Published: Jun 10, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The process_frame_obj function in sanm.c in libavcodec in FFmpeg before 1.2.1 does not validate width and height values, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) via crafted LucasArts Smush video data.

Affected (1)

Products: Ffmpeg: Ffmpeg
1 product
Ffmpeg
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.2

Timeline

No history available yet.