Buffer Overflow Affecting ffmpeg package, versions [,1.1.4)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.56% (78th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-FFMPEG-2368931
  • published26 Jan 2022
  • disclosed23 Feb 2013
  • creditUnknown

Introduced: 23 Feb 2013

CVE-2013-0894  (opens in a new tab)
CWE-120  (opens in a new tab)

How to fix?

Upgrade ffmpeg to version 1.1.4 or higher.

Overview

Affected versions of this package are vulnerable to Buffer Overflow. Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (divide-by-zero error or out-of-bounds array access) or possibly have unspecified other impact via vectors involving a zero value for a bark map size.

References

CVSS Scores

version 3.1